Smlouvy Dotace Platy Úřady Zakázky Sponzoři & firmy PastVina 
❤ Podpořte nás Přihlásit se Registrace

Hlídač Portál o VZ a koncesích Detailní analýza HTTPs pro Portál o VZ a koncesích

Portál o VZ a koncesích
http://www.portal-vz.cz/

Ministerstvo pro místní rozvoj Portál nabízí komplexní a přehledné informace týkající se zadávání veřejných zakázek. Komplexně řešený je zde informační systém o veřejných zakázkách, pod kterým se nachází přístup k Věstníku veřejných zakázek, k seznamu kvalifikovaných dodavatelů a systémům certifikovaných dodavatelů, ke statistikám veřejných zakázek, k rejstříku koncesních smluv, přístup ke klasifikacím a číselníkům. Dostupný je zde také rejstřík osob se zákazem plnění veřejných zakázek resp. rejstřík osob se zákazem plnění koncesních smluv. Lze vyhledávat subjekty dle různých parametrů. Portál neomezeným dálkovým přístupem bezplatně zpřístupňuje informace usnadňující zadavatelům i dodavatelům veřejných zakázek své aktivity prostřednictvím internetu. Údaje jsou ve formátu otevřených dat.


Zabezpečení komunikace

A
Certifikát expiruje za 20 dní.

Výsledek analýzy HTTPS na www.portal-vz.cz ze dne 17.06.2026

Všechno je v nejlepším pořádku a web se drží doporučených postupů.


Detailní analýza

Detailní report z HTTPs analýzy pomocí nástroje testssl.sh

server www.portal-vz.cz/185.8.237.6
pre_128cipher INFO {
No 128 cipher limit bug
}
SSLv2 OK {
not offered
}
SSLv3 OK {
not offered
}
TLS1 INFO {
not offered
}
TLS1_1 INFO {
not offered
}
TLS1_2 OK {
offered
}
TLS1_3 OK {
offered with final
}
NPN INFO {
not offered
}
ALPN_HTTP2 OK {
h2
}
ALPN INFO {
http/1.1
}
cipherlist_NULL
zranitelnosti: CWE-327
OK {
not offered
}
cipherlist_aNULL
zranitelnosti: CWE-327
OK {
not offered
}
cipherlist_EXPORT
zranitelnosti: CWE-327
OK {
not offered
}
cipherlist_LOW
zranitelnosti: CWE-327
OK {
not offered
}
cipherlist_3DES_IDEA
zranitelnosti: CWE-310
INFO {
not offered
}
cipherlist_AVERAGE
zranitelnosti: CWE-310
INFO {
not offered
}
cipherlist_GOOD INFO {
not offered
}
cipherlist_STRONG OK {
offered
}
cipher_order OK {
server
}
protocol_negotiated OK {
Default protocol TLS1.3
}
cipher_negotiated OK {
TLS_CHACHA20_POLY1305_SHA256, 253 bit ECDH (X25519)
}
cipher-tls1_2_xcca8 OK {
TLSv1.2   xcca8   ECDHE-RSA-CHACHA20-POLY1305       ECDH 253   ChaCha20    256      TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256
}
cipher-tls1_2_xc030 OK {
TLSv1.2   xc030   ECDHE-RSA-AES256-GCM-SHA384       ECDH 253   AESGCM      256      TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
}
cipher-tls1_2_xc02f OK {
TLSv1.2   xc02f   ECDHE-RSA-AES128-GCM-SHA256       ECDH 253   AESGCM      128      TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
}
cipherorder_TLSv1_2 INFO {
ECDHE-RSA-CHACHA20-POLY1305 ECDHE-RSA-AES256-GCM-SHA384 ECDHE-RSA-AES128-GCM-SHA256
}
cipher-tls1_3_x1303 OK {
TLSv1.3   x1303   TLS_CHACHA20_POLY1305_SHA256      ECDH 253   ChaCha20    256      TLS_CHACHA20_POLY1305_SHA256
}
cipher-tls1_3_x1302 OK {
TLSv1.3   x1302   TLS_AES_256_GCM_SHA384            ECDH 253   AESGCM      256      TLS_AES_256_GCM_SHA384
}
cipher-tls1_3_x1301 OK {
TLSv1.3   x1301   TLS_AES_128_GCM_SHA256            ECDH 253   AESGCM      128      TLS_AES_128_GCM_SHA256
}
cipherorder_TLSv1_3 INFO {
TLS_CHACHA20_POLY1305_SHA256 TLS_AES_256_GCM_SHA384 TLS_AES_128_GCM_SHA256
}
FS OK {
offered
}
FS_ciphers INFO {
TLS_AES_256_GCM_SHA384 TLS_CHACHA20_POLY1305_SHA256 ECDHE-RSA-AES256-GCM-SHA384 ECDHE-RSA-CHACHA20-POLY1305 TLS_AES_128_GCM_SHA256 ECDHE-RSA-AES128-GCM-SHA256
}
FS_ECDHE_curves OK {
prime256v1 X25519
}
TLS_extensions INFO {
'renegotiation info/#65281' 'server name/#0' 'EC point formats/#11' 'session ticket/#35' 'supported versions/#43' 'key share/#51' 'supported_groups/#10' 'max fragment length/#1' 'application layer protocol negotiation/#16' 'extended master secret/#23'
}
TLS_session_ticket INFO {
valid for 1800 seconds only (<daily)
}
SSL_sessionID_support INFO {
yes
}
sessionresumption_ticket INFO {
not supported
}
sessionresumption_ID INFO {
supported
}
TLS_timestamp INFO {
random
}
certificate_compression INFO {
none
}
clientAuth INFO {
none
}
cert_numbers INFO {
1
}
cert_signatureAlgorithm OK {
SHA256 with RSA
}
cert_keySize INFO {
RSA 2048 bits (exponent is 65537)
}
cert_keyUsage INFO {
Digital Signature, Key Encipherment
}
cert_extKeyUsage INFO {
TLS Web Server Authentication
}
cert_serialNumber INFO {
059F5CCE334BBCACFDDBC82FF587662F1550
}
cert_serialNumberLen INFO {
18
}
cert_fingerprintSHA1 INFO {
F57AD0456AD8DC34BD582FD7DE9FEA99722906EB
}
cert_fingerprintSHA256 INFO {
24A01750DA39CC17A1C9596BDF5D39424227F8DB025545184D48711C1FC71FEE
}
cert INFO {
-----BEGIN CERTIFICATE----- MIIFATCCA+mgAwIBAgISBZ9czjNLvKz928gv9YdmLxVQMA0GCSqGSIb3DQEBCwUA MDMxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MQwwCgYDVQQD EwNSMTIwHhcNMjYwNDEwMTMwOTQwWhcNMjYwNzA5MTMwOTM5WjAXMRUwEwYDVQQD Ewxwb3J0YWwtdnouY3owggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC3 q5WR6X//TE2+IyofH+tcc7hmzcPHk26a0YowLr+I9Vupq4DK2Q3x6yohQokb1jrH NTjOl83dv5isZBcE17ucHOVMVwb/PCpED9a35/jxyF0VBfHM2bHTbGQ2GbNkcgpR IzEEIB/GviogyuyDhOjeli3Hzx6TP/7DWGSWQxIIRTIP9E/u1bCF5J9BC7LZ+AOe 3BfnX8zxsu+B4jlDIxG4waYRzPSLAs8qdCAwjZXueyFx6+eZHt6em/Tg7ginTKeG iVPMLTC0LIhYB82oLEg9XSsVeXSkb8Htrf911pz0LkNZnY/OSc4ECqI/1Zy6da4y F2vkuxfXpepdAgqLeVW1AgMBAAGjggIpMIICJTAOBgNVHQ8BAf8EBAMCBaAwEwYD VR0lBAwwCgYIKwYBBQUHAwEwDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQUkVjmKYi+ YOfsInhEpYMo3yXufN4wHwYDVR0jBBgwFoAUALUp8i2ObzHom0yteD763OkM0dIw MwYIKwYBBQUHAQEEJzAlMCMGCCsGAQUFBzAChhdodHRwOi8vcjEyLmkubGVuY3Iu b3JnLzAnBgNVHREEIDAegg4qLnBvcnRhbC12ei5jeoIMcG9ydGFsLXZ6LmN6MBMG A1UdIAQMMAowCAYGZ4EMAQIBMC4GA1UdHwQnMCUwI6AhoB+GHWh0dHA6Ly9yMTIu Yy5sZW5jci5vcmcvODEuY3JsMIIBCwYKKwYBBAHWeQIEAgSB/ASB+QD3AHYAyzj3 FYl8hKFEX1vB3fvJbvKaWc1HCmkFhbDLFMMUWOcAAAGdd7jDoQAABAMARzBFAiAm HCdlm4adWBN8NMb3HT3zmqc6opUsjNgJYxcrEnhQBgIhAI9c7BXEMgtEB4Zdv0wK mou4Amz/5K84NBdGIPJO2uj7AH0AbP5QGUOoXqkWvFLRM+TcyR7xQRx9JYQg0XOA nhgY6zoAAAGdd7jFjgAIAAAFAAadNkIEAwBGMEQCIFgI+Ird+lezsEIW1tlIAvkx CzTdABScjX+NMFvlwTilAiBNWlSx7YhkWzHESyRqoCPLdAmZumLxzTOeO4rBo7+z czANBgkqhkiG9w0BAQsFAAOCAQEArcKiD5K4dtpuJWoMe3bHbQk8gBedean1yYqI LT+8imF3z1rx12NI8OuMRQSY5zqDgMULnv8r50tUVtLNJP3Gk8dKWmPLhpeGhO1b QPx8y4oj9lE5N1S4VpGiuS8w7lTiUIIGz6BrndTLlr8LuMyLN5uA6xFJRqbdH49r Jv+NBP+xPK+QgoGyL7VepZJKOuPUFQh8RhntwLPGsKKEVl6X9KuQuMz71ttRlFBq uQGUEeUGPP2jWapcgYao+aYcec8Un5XwDb76mwbDTNHfeyiOqvVcuy1ca8pkoExq GMRMcsjvt3ZGulKbnTYeVXbwaAgkYyIj7WOc7WnB1/pKfJgeOA== -----END CERTIFICATE-----
}
cert_commonName OK {
portal-vz.cz
}
cert_commonName_wo_SNI INFO {
request w/o SNI didn't succeed
}
cert_subjectAltName INFO {
*.portal-vz.cz portal-vz.cz
}
cert_trust OK {
Ok via SAN wildcard (SNI mandatory)
}
cert_chain_of_trust OK {
passed.
}
cert_certificatePolicies_EV INFO {
no
}
cert_expirationStatus MEDIUM {
expires < 30 days (21)
}
cert_notBefore INFO {
2026-04-10 13:09
}
cert_notAfter MEDIUM {
2026-07-09 13:09
}
cert_extlifeSpan OK {
certificate has no extended life time according to browser forum
}
cert_eTLS INFO {
not present
}
cert_crlDistributionPoints INFO {
http://r12.c.lencr.org/81.crl
}
cert_ocspURL INFO {
--
}
OCSP_stapling INFO {
not offered
}
cert_mustStapleExtension INFO {
--
}
DNS_CAArecord LOW {
--
}
certificate_transparency OK {
yes (certificate extension)
}
certs_countServer INFO {
2
}
certs_list_ordering_problem INFO {
no
}
cert_caIssuers INFO {
R12 (Let's Encrypt from US)
}
intermediate_cert <#1> INFO {
-----BEGIN CERTIFICATE----- MIIFBjCCAu6gAwIBAgIRAMISMktwqbSRcdxA9+KFJjwwDQYJKoZIhvcNAQELBQAw TzELMAkGA1UEBhMCVVMxKTAnBgNVBAoTIEludGVybmV0IFNlY3VyaXR5IFJlc2Vh cmNoIEdyb3VwMRUwEwYDVQQDEwxJU1JHIFJvb3QgWDEwHhcNMjQwMzEzMDAwMDAw WhcNMjcwMzEyMjM1OTU5WjAzMQswCQYDVQQGEwJVUzEWMBQGA1UEChMNTGV0J3Mg RW5jcnlwdDEMMAoGA1UEAxMDUjEyMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIB CgKCAQEA2pgodK2+lP474B7i5Ut1qywSf+2nAzJ+Npfs6DGPpRONC5kuHs0BUT1M 5ShuCVUxqqUiXXL0LQfCTUA83wEjuXg39RplMjTmhnGdBO+ECFu9AhqZ66YBAJpz kG2Pogeg0JfT2kVhgTU9FPnEwF9q3AuWGrCf4yrqvSrWmMebcas7dA8827JgvlpL Thjp2ypzXIlhZZ7+7Tymy05v5J75AEaz/xlNKmOzjmbGGIVwx1Blbzt05UiDDwhY XS0jnV6j/ujbAKHS9OMZTfLuevYnnuXNnC2i8n+cF63vEzc50bTILEHWhsDp7CH4 WRt/uTp8n1wBnWIEwii9Cq08yhDsGwIDAQABo4H4MIH1MA4GA1UdDwEB/wQEAwIB hjAdBgNVHSUEFjAUBggrBgEFBQcDAgYIKwYBBQUHAwEwEgYDVR0TAQH/BAgwBgEB /wIBADAdBgNVHQ4EFgQUALUp8i2ObzHom0yteD763OkM0dIwHwYDVR0jBBgwFoAU ebRZ5nu25eQBc4AIiMgaWPbpm24wMgYIKwYBBQUHAQEEJjAkMCIGCCsGAQUFBzAC hhZodHRwOi8veDEuaS5sZW5jci5vcmcvMBMGA1UdIAQMMAowCAYGZ4EMAQIBMCcG A1UdHwQgMB4wHKAaoBiGFmh0dHA6Ly94MS5jLmxlbmNyLm9yZy8wDQYJKoZIhvcN AQELBQADggIBAI910AnPanZIZTKS3rVEyIV29BWEjAK/duuz8eL5boSoVpHhkkv3 4eoAeEiPdZLj5EZ7G2ArIK+gzhTlRQ1q4FKGpPPaFBSpqV/xbUb5UlAXQOnkHn3m FVj+qYv87/WeY+Bm4sN3Ox8BhyaU7UAQ3LeZ7N1X01xxQe4wIAAE3JVLUCiHmZL+ qoCUtgYIFPgcg350QMUIWgxPXNGEncT921ne7nluI02V8pLUmClqXOsCwULw+PVO ZCB7qOMxxMBoCUeL2Ll4oMpOSr5pJCpLN3tRA2s6P1KLs9TSrVhOk+7LX28NMUlI usQ/nxLJID0RhAeFtPjyOCOscQBA53+NRjSCak7P4A5jX7ppmkcJECL+S0i3kXVU y5Me5BbrU8973jZNv/ax6+ZK6TM8jWmimL6of6OrX7ZU6E2WqazzsFrLG3o2kySb zlhSgJ81Cl4tv3SbYiYXnJExKQvzf83DYotox3f0fwv7xln1A2ZLplCb0O+l/AK0 YE0DS2FPxSAHi0iwMfW2nNHJrXcY3LLHD77gRgje4Eveubi2xxa+Nmk/hmhLdIET iVDFanoCrMVIpQ59XWHkzdFmoHXHBV7oibVjGSO7ULSQ7MJ1Nz51phuDJSgAIU7A 0zrLnOrAj/dfrlEWRhCvAgbuwLZX1A2sjNjXoPOHbsPiy+lO1KF8/XY7 -----END CERTIFICATE-----
}
intermediate_cert_fingerprintSHA256 <#1> INFO {
131FCE7784016899A5A00203A9EFC80F18EBBD75580717EDC1553580930836EC
}
intermediate_cert_notBefore <#1> INFO {
2024-03-13 00:00
}
intermediate_cert_notAfter <#1> OK {
2027-03-12 23:59
}
intermediate_cert_expiration <#1> OK {
ok > 40 days
}
intermediate_cert_chain <#1> INFO {
R12 <-- ISRG Root X1
}
intermediate_cert_badOCSP OK {
intermediate certificate(s) is/are ok
}
HTTP_status_code INFO {
301 Moved Permanently ('/')
}
HTTP_clock_skew INFO {
-3 seconds from localtime
}
HTTP_headerTime INFO {
1781726840
}
HTTP_headerAge INFO {
0 seconds
}
HSTS LOW {
not offered
}
HPKP INFO {
No support for HTTP Public Key Pinning
}
banner_server INFO {
Apache
}
banner_application INFO {
No application banner found
}
cookie_count INFO {
2 at '/' (30x detected, better try target URL of 30x)
}
cookie_secure INFO {
0/2 at '/' marked as secure
}
cookie_httponly INFO {
0/2 at '/' marked as HttpOnly (30x detected, better try target URL of 30x)
}
Cache-Control INFO {
no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate
}
Pragma INFO {
no-cache
}
banner_reverseproxy
zranitelnosti: CWE-200
INFO {
x-cacheable: NO:Set-Cookie
}
heartbleed
zranitelnosti: CVE-2014-0160 CWE-119
OK {
not vulnerable, no heartbeat extension
}
CCS
zranitelnosti: CVE-2014-0224 CWE-310
OK {
not vulnerable
}
ticketbleed
zranitelnosti: CVE-2016-9244 CWE-200
OK {
not vulnerable
}
ROBOT OK {
not vulnerable, no RSA key transport cipher
}
secure_renego
zranitelnosti: CWE-310
WARN {
OpenSSL handshake didn't succeed
}
secure_client_renego
zranitelnosti: CVE-2011-1473 CWE-310
OK {
not vulnerable
}
CRIME_TLS
zranitelnosti: CVE-2012-4929 CWE-310
OK {
not vulnerable
}
BREACH
zranitelnosti: CVE-2013-3587 CWE-310
OK {
not vulnerable, no gzip/deflate/compress/br HTTP compression  - only supplied '/' tested
}
POODLE_SSL
zranitelnosti: CVE-2014-3566 CWE-310
OK {
not vulnerable, no SSLv3
}
fallback_SCSV OK {
no protocol below TLS 1.2 offered
}
SWEET32 OK {
not vulnerable
}
FREAK
zranitelnosti: CVE-2015-0204 CWE-310
OK {
not vulnerable
}
DROWN OK {
not vulnerable on this host and port
}
DROWN_hint INFO {
Make sure you don't use this certificate elsewhere with SSLv2 enabled services, see https://censys.io/ipv4?q=24A01750DA39CC17A1C9596BDF5D39424227F8DB025545184D48711C1FC71FEE
}
LOGJAM
zranitelnosti: CVE-2015-4000 CWE-310
OK {
not vulnerable, no DH EXPORT ciphers,
}
LOGJAM-common_primes
zranitelnosti: CVE-2015-4000 CWE-310
OK {
no DH key with <= TLS 1.2
}
BEAST
zranitelnosti: CVE-2011-3389 CWE-20
OK {
not vulnerable, no SSL3 or TLS1
}
LUCKY13
zranitelnosti: CVE-2013-0169 CWE-310
OK {
not vulnerable
}
winshock
zranitelnosti: CVE-2014-6321 CWE-94
OK {
not vulnerable
}
RC4 OK {
not vulnerable
}
clientsimulation-android_442 INFO {
TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
}
clientsimulation-android_500 INFO {
TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256
}
clientsimulation-android_60 INFO {
TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256
}
clientsimulation-android_70 INFO {
TLSv1.2 ECDHE-RSA-CHACHA20-POLY1305
}
clientsimulation-android_81 INFO {
TLSv1.2 ECDHE-RSA-CHACHA20-POLY1305
}
clientsimulation-android_90 INFO {
TLSv1.3 TLS_CHACHA20_POLY1305_SHA256
}
clientsimulation-android_X INFO {
TLSv1.3 TLS_CHACHA20_POLY1305_SHA256
}
clientsimulation-chrome_74_win10 INFO {
TLSv1.3 TLS_CHACHA20_POLY1305_SHA256
}
clientsimulation-chrome_79_win10 INFO {
TLSv1.3 TLS_CHACHA20_POLY1305_SHA256
}
clientsimulation-firefox_66_win81 INFO {
TLSv1.3 TLS_CHACHA20_POLY1305_SHA256
}
clientsimulation-firefox_71_win10 INFO {
TLSv1.3 TLS_CHACHA20_POLY1305_SHA256
}
clientsimulation-ie_6_xp INFO {
No connection
}
clientsimulation-ie_8_win7 INFO {
No connection
}
clientsimulation-ie_8_xp INFO {
No connection
}
clientsimulation-ie_11_win7 INFO {
No connection
}
clientsimulation-ie_11_win81 INFO {
No connection
}
clientsimulation-ie_11_winphone81 INFO {
No connection
}
clientsimulation-ie_11_win10 INFO {
TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
}
clientsimulation-edge_15_win10 INFO {
TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
}
clientsimulation-edge_17_win10 INFO {
TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
}
clientsimulation-opera_66_win10 INFO {
TLSv1.3 TLS_CHACHA20_POLY1305_SHA256
}
clientsimulation-safari_9_ios9 INFO {
TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
}
clientsimulation-safari_9_osx1011 INFO {
TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
}
clientsimulation-safari_10_osx1012 INFO {
TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
}
clientsimulation-safari_121_ios_122 INFO {
TLSv1.3 TLS_CHACHA20_POLY1305_SHA256
}
clientsimulation-safari_130_osx_10146 INFO {
TLSv1.3 TLS_CHACHA20_POLY1305_SHA256
}
clientsimulation-apple_ats_9_ios9 INFO {
TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
}
clientsimulation-java_6u45 INFO {
No connection
}
clientsimulation-java_7u25 INFO {
No connection
}
clientsimulation-java_8u161 INFO {
TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
}
clientsimulation-java1102 INFO {
TLSv1.3 TLS_AES_256_GCM_SHA384
}
clientsimulation-java1201 INFO {
TLSv1.3 TLS_CHACHA20_POLY1305_SHA256
}
clientsimulation-openssl_102e INFO {
TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
}
clientsimulation-openssl_110l INFO {
TLSv1.2 ECDHE-RSA-CHACHA20-POLY1305
}
clientsimulation-openssl_111d INFO {
TLSv1.3 TLS_CHACHA20_POLY1305_SHA256
}
clientsimulation-thunderbird_68_3_1 INFO {
TLSv1.3 TLS_CHACHA20_POLY1305_SHA256
}
rating_spec INFO {
SSL Labs's 'SSL Server Rating Guide' (version 2009q from 2020-01-30)
}
rating_doc INFO {
https://github.com/ssllabs/research/wiki/SSL-Server-Rating-Guide
}
protocol_support_score INFO {
100
}
protocol_support_score_weighted INFO {
30
}
key_exchange_score INFO {
90
}
key_exchange_score_weighted INFO {
27
}
cipher_strength_score INFO {
90
}
cipher_strength_score_weighted INFO {
36
}
final_score INFO {
93
}
overall_grade OK {
A
}
grade_cap_reason_1 INFO {
Grade capped to A. HSTS is not offered
}
server www.portal-vz.cz/185.8.237.5
pre_128cipher INFO {
No 128 cipher limit bug
}
SSLv2 OK {
not offered
}
SSLv3 OK {
not offered
}
TLS1 INFO {
not offered
}
TLS1_1 INFO {
not offered
}
TLS1_2 OK {
offered
}
TLS1_3 OK {
offered with final
}
NPN INFO {
not offered
}
ALPN_HTTP2 OK {
h2
}
ALPN INFO {
http/1.1
}
cipherlist_NULL
zranitelnosti: CWE-327
OK {
not offered
}
cipherlist_aNULL
zranitelnosti: CWE-327
OK {
not offered
}
cipherlist_EXPORT
zranitelnosti: CWE-327
OK {
not offered
}
cipherlist_LOW
zranitelnosti: CWE-327
OK {
not offered
}
cipherlist_3DES_IDEA
zranitelnosti: CWE-310
INFO {
not offered
}
cipherlist_AVERAGE
zranitelnosti: CWE-310
INFO {
not offered
}
cipherlist_GOOD INFO {
not offered
}
cipherlist_STRONG OK {
offered
}
cipher_order OK {
server
}
protocol_negotiated OK {
Default protocol TLS1.3
}
cipher_negotiated OK {
TLS_CHACHA20_POLY1305_SHA256, 253 bit ECDH (X25519)
}
cipher-tls1_2_xcca8 OK {
TLSv1.2   xcca8   ECDHE-RSA-CHACHA20-POLY1305       ECDH 253   ChaCha20    256      TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256
}
cipher-tls1_2_xc030 OK {
TLSv1.2   xc030   ECDHE-RSA-AES256-GCM-SHA384       ECDH 253   AESGCM      256      TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
}
cipher-tls1_2_xc02f OK {
TLSv1.2   xc02f   ECDHE-RSA-AES128-GCM-SHA256       ECDH 253   AESGCM      128      TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
}
cipherorder_TLSv1_2 INFO {
ECDHE-RSA-CHACHA20-POLY1305 ECDHE-RSA-AES256-GCM-SHA384 ECDHE-RSA-AES128-GCM-SHA256
}
cipher-tls1_3_x1303 OK {
TLSv1.3   x1303   TLS_CHACHA20_POLY1305_SHA256      ECDH 253   ChaCha20    256      TLS_CHACHA20_POLY1305_SHA256
}
cipher-tls1_3_x1302 OK {
TLSv1.3   x1302   TLS_AES_256_GCM_SHA384            ECDH 253   AESGCM      256      TLS_AES_256_GCM_SHA384
}
cipher-tls1_3_x1301 OK {
TLSv1.3   x1301   TLS_AES_128_GCM_SHA256            ECDH 253   AESGCM      128      TLS_AES_128_GCM_SHA256
}
cipherorder_TLSv1_3 INFO {
TLS_CHACHA20_POLY1305_SHA256 TLS_AES_256_GCM_SHA384 TLS_AES_128_GCM_SHA256
}
FS OK {
offered
}
FS_ciphers INFO {
TLS_AES_256_GCM_SHA384 TLS_CHACHA20_POLY1305_SHA256 ECDHE-RSA-AES256-GCM-SHA384 ECDHE-RSA-CHACHA20-POLY1305 TLS_AES_128_GCM_SHA256 ECDHE-RSA-AES128-GCM-SHA256
}
FS_ECDHE_curves OK {
prime256v1 X25519
}
TLS_extensions INFO {
'renegotiation info/#65281' 'server name/#0' 'EC point formats/#11' 'session ticket/#35' 'supported versions/#43' 'key share/#51' 'supported_groups/#10' 'max fragment length/#1' 'application layer protocol negotiation/#16' 'extended master secret/#23'
}
TLS_session_ticket INFO {
valid for 1800 seconds only (<daily)
}
SSL_sessionID_support INFO {
yes
}
sessionresumption_ticket INFO {
not supported
}
sessionresumption_ID INFO {
not supported
}
TLS_timestamp INFO {
random
}
certificate_compression INFO {
none
}
clientAuth INFO {
none
}
cert_numbers INFO {
1
}
cert_signatureAlgorithm OK {
SHA256 with RSA
}
cert_keySize INFO {
RSA 2048 bits (exponent is 65537)
}
cert_keyUsage INFO {
Digital Signature, Key Encipherment
}
cert_extKeyUsage INFO {
TLS Web Server Authentication
}
cert_serialNumber INFO {
059F5CCE334BBCACFDDBC82FF587662F1550
}
cert_serialNumberLen INFO {
18
}
cert_fingerprintSHA1 INFO {
F57AD0456AD8DC34BD582FD7DE9FEA99722906EB
}
cert_fingerprintSHA256 INFO {
24A01750DA39CC17A1C9596BDF5D39424227F8DB025545184D48711C1FC71FEE
}
cert INFO {
-----BEGIN CERTIFICATE----- MIIFATCCA+mgAwIBAgISBZ9czjNLvKz928gv9YdmLxVQMA0GCSqGSIb3DQEBCwUA MDMxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MQwwCgYDVQQD EwNSMTIwHhcNMjYwNDEwMTMwOTQwWhcNMjYwNzA5MTMwOTM5WjAXMRUwEwYDVQQD Ewxwb3J0YWwtdnouY3owggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC3 q5WR6X//TE2+IyofH+tcc7hmzcPHk26a0YowLr+I9Vupq4DK2Q3x6yohQokb1jrH NTjOl83dv5isZBcE17ucHOVMVwb/PCpED9a35/jxyF0VBfHM2bHTbGQ2GbNkcgpR IzEEIB/GviogyuyDhOjeli3Hzx6TP/7DWGSWQxIIRTIP9E/u1bCF5J9BC7LZ+AOe 3BfnX8zxsu+B4jlDIxG4waYRzPSLAs8qdCAwjZXueyFx6+eZHt6em/Tg7ginTKeG iVPMLTC0LIhYB82oLEg9XSsVeXSkb8Htrf911pz0LkNZnY/OSc4ECqI/1Zy6da4y F2vkuxfXpepdAgqLeVW1AgMBAAGjggIpMIICJTAOBgNVHQ8BAf8EBAMCBaAwEwYD VR0lBAwwCgYIKwYBBQUHAwEwDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQUkVjmKYi+ YOfsInhEpYMo3yXufN4wHwYDVR0jBBgwFoAUALUp8i2ObzHom0yteD763OkM0dIw MwYIKwYBBQUHAQEEJzAlMCMGCCsGAQUFBzAChhdodHRwOi8vcjEyLmkubGVuY3Iu b3JnLzAnBgNVHREEIDAegg4qLnBvcnRhbC12ei5jeoIMcG9ydGFsLXZ6LmN6MBMG A1UdIAQMMAowCAYGZ4EMAQIBMC4GA1UdHwQnMCUwI6AhoB+GHWh0dHA6Ly9yMTIu Yy5sZW5jci5vcmcvODEuY3JsMIIBCwYKKwYBBAHWeQIEAgSB/ASB+QD3AHYAyzj3 FYl8hKFEX1vB3fvJbvKaWc1HCmkFhbDLFMMUWOcAAAGdd7jDoQAABAMARzBFAiAm HCdlm4adWBN8NMb3HT3zmqc6opUsjNgJYxcrEnhQBgIhAI9c7BXEMgtEB4Zdv0wK mou4Amz/5K84NBdGIPJO2uj7AH0AbP5QGUOoXqkWvFLRM+TcyR7xQRx9JYQg0XOA nhgY6zoAAAGdd7jFjgAIAAAFAAadNkIEAwBGMEQCIFgI+Ird+lezsEIW1tlIAvkx CzTdABScjX+NMFvlwTilAiBNWlSx7YhkWzHESyRqoCPLdAmZumLxzTOeO4rBo7+z czANBgkqhkiG9w0BAQsFAAOCAQEArcKiD5K4dtpuJWoMe3bHbQk8gBedean1yYqI LT+8imF3z1rx12NI8OuMRQSY5zqDgMULnv8r50tUVtLNJP3Gk8dKWmPLhpeGhO1b QPx8y4oj9lE5N1S4VpGiuS8w7lTiUIIGz6BrndTLlr8LuMyLN5uA6xFJRqbdH49r Jv+NBP+xPK+QgoGyL7VepZJKOuPUFQh8RhntwLPGsKKEVl6X9KuQuMz71ttRlFBq uQGUEeUGPP2jWapcgYao+aYcec8Un5XwDb76mwbDTNHfeyiOqvVcuy1ca8pkoExq GMRMcsjvt3ZGulKbnTYeVXbwaAgkYyIj7WOc7WnB1/pKfJgeOA== -----END CERTIFICATE-----
}
cert_commonName OK {
portal-vz.cz
}
cert_commonName_wo_SNI INFO {
request w/o SNI didn't succeed
}
cert_subjectAltName INFO {
*.portal-vz.cz portal-vz.cz
}
cert_trust OK {
Ok via SAN wildcard (SNI mandatory)
}
cert_chain_of_trust OK {
passed.
}
cert_certificatePolicies_EV INFO {
no
}
cert_expirationStatus MEDIUM {
expires < 30 days (21)
}
cert_notBefore INFO {
2026-04-10 13:09
}
cert_notAfter MEDIUM {
2026-07-09 13:09
}
cert_extlifeSpan OK {
certificate has no extended life time according to browser forum
}
cert_eTLS INFO {
not present
}
cert_crlDistributionPoints INFO {
http://r12.c.lencr.org/81.crl
}
cert_ocspURL INFO {
--
}
OCSP_stapling INFO {
not offered
}
cert_mustStapleExtension INFO {
--
}
DNS_CAArecord LOW {
--
}
certificate_transparency OK {
yes (certificate extension)
}
certs_countServer INFO {
2
}
certs_list_ordering_problem INFO {
no
}
cert_caIssuers INFO {
R12 (Let's Encrypt from US)
}
intermediate_cert <#1> INFO {
-----BEGIN CERTIFICATE----- MIIFBjCCAu6gAwIBAgIRAMISMktwqbSRcdxA9+KFJjwwDQYJKoZIhvcNAQELBQAw TzELMAkGA1UEBhMCVVMxKTAnBgNVBAoTIEludGVybmV0IFNlY3VyaXR5IFJlc2Vh cmNoIEdyb3VwMRUwEwYDVQQDEwxJU1JHIFJvb3QgWDEwHhcNMjQwMzEzMDAwMDAw WhcNMjcwMzEyMjM1OTU5WjAzMQswCQYDVQQGEwJVUzEWMBQGA1UEChMNTGV0J3Mg RW5jcnlwdDEMMAoGA1UEAxMDUjEyMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIB CgKCAQEA2pgodK2+lP474B7i5Ut1qywSf+2nAzJ+Npfs6DGPpRONC5kuHs0BUT1M 5ShuCVUxqqUiXXL0LQfCTUA83wEjuXg39RplMjTmhnGdBO+ECFu9AhqZ66YBAJpz kG2Pogeg0JfT2kVhgTU9FPnEwF9q3AuWGrCf4yrqvSrWmMebcas7dA8827JgvlpL Thjp2ypzXIlhZZ7+7Tymy05v5J75AEaz/xlNKmOzjmbGGIVwx1Blbzt05UiDDwhY XS0jnV6j/ujbAKHS9OMZTfLuevYnnuXNnC2i8n+cF63vEzc50bTILEHWhsDp7CH4 WRt/uTp8n1wBnWIEwii9Cq08yhDsGwIDAQABo4H4MIH1MA4GA1UdDwEB/wQEAwIB hjAdBgNVHSUEFjAUBggrBgEFBQcDAgYIKwYBBQUHAwEwEgYDVR0TAQH/BAgwBgEB /wIBADAdBgNVHQ4EFgQUALUp8i2ObzHom0yteD763OkM0dIwHwYDVR0jBBgwFoAU ebRZ5nu25eQBc4AIiMgaWPbpm24wMgYIKwYBBQUHAQEEJjAkMCIGCCsGAQUFBzAC hhZodHRwOi8veDEuaS5sZW5jci5vcmcvMBMGA1UdIAQMMAowCAYGZ4EMAQIBMCcG A1UdHwQgMB4wHKAaoBiGFmh0dHA6Ly94MS5jLmxlbmNyLm9yZy8wDQYJKoZIhvcN AQELBQADggIBAI910AnPanZIZTKS3rVEyIV29BWEjAK/duuz8eL5boSoVpHhkkv3 4eoAeEiPdZLj5EZ7G2ArIK+gzhTlRQ1q4FKGpPPaFBSpqV/xbUb5UlAXQOnkHn3m FVj+qYv87/WeY+Bm4sN3Ox8BhyaU7UAQ3LeZ7N1X01xxQe4wIAAE3JVLUCiHmZL+ qoCUtgYIFPgcg350QMUIWgxPXNGEncT921ne7nluI02V8pLUmClqXOsCwULw+PVO ZCB7qOMxxMBoCUeL2Ll4oMpOSr5pJCpLN3tRA2s6P1KLs9TSrVhOk+7LX28NMUlI usQ/nxLJID0RhAeFtPjyOCOscQBA53+NRjSCak7P4A5jX7ppmkcJECL+S0i3kXVU y5Me5BbrU8973jZNv/ax6+ZK6TM8jWmimL6of6OrX7ZU6E2WqazzsFrLG3o2kySb zlhSgJ81Cl4tv3SbYiYXnJExKQvzf83DYotox3f0fwv7xln1A2ZLplCb0O+l/AK0 YE0DS2FPxSAHi0iwMfW2nNHJrXcY3LLHD77gRgje4Eveubi2xxa+Nmk/hmhLdIET iVDFanoCrMVIpQ59XWHkzdFmoHXHBV7oibVjGSO7ULSQ7MJ1Nz51phuDJSgAIU7A 0zrLnOrAj/dfrlEWRhCvAgbuwLZX1A2sjNjXoPOHbsPiy+lO1KF8/XY7 -----END CERTIFICATE-----
}
intermediate_cert_fingerprintSHA256 <#1> INFO {
131FCE7784016899A5A00203A9EFC80F18EBBD75580717EDC1553580930836EC
}
intermediate_cert_notBefore <#1> INFO {
2024-03-13 00:00
}
intermediate_cert_notAfter <#1> OK {
2027-03-12 23:59
}
intermediate_cert_expiration <#1> OK {
ok > 40 days
}
intermediate_cert_chain <#1> INFO {
R12 <-- ISRG Root X1
}
intermediate_cert_badOCSP OK {
intermediate certificate(s) is/are ok
}
HTTP_status_code INFO {
301 Moved Permanently ('/')
}
HTTP_clock_skew INFO {
-1 seconds from localtime
}
HTTP_headerTime INFO {
1781727078
}
HTTP_headerAge INFO {
0 seconds
}
HSTS LOW {
not offered
}
HPKP INFO {
No support for HTTP Public Key Pinning
}
banner_server INFO {
Apache
}
banner_application INFO {
No application banner found
}
cookie_count INFO {
2 at '/' (30x detected, better try target URL of 30x)
}
cookie_secure INFO {
0/2 at '/' marked as secure
}
cookie_httponly INFO {
0/2 at '/' marked as HttpOnly (30x detected, better try target URL of 30x)
}
Cache-Control INFO {
no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate
}
Pragma INFO {
no-cache
}
banner_reverseproxy
zranitelnosti: CWE-200
INFO {
x-cacheable: NO:Set-Cookie
}
heartbleed
zranitelnosti: CVE-2014-0160 CWE-119
OK {
not vulnerable, no heartbeat extension
}
CCS
zranitelnosti: CVE-2014-0224 CWE-310
OK {
not vulnerable
}
ticketbleed
zranitelnosti: CVE-2016-9244 CWE-200
OK {
not vulnerable
}
ROBOT OK {
not vulnerable, no RSA key transport cipher
}
secure_renego
zranitelnosti: CWE-310
WARN {
OpenSSL handshake didn't succeed
}
secure_client_renego
zranitelnosti: CVE-2011-1473 CWE-310
OK {
not vulnerable
}
CRIME_TLS
zranitelnosti: CVE-2012-4929 CWE-310
OK {
not vulnerable
}
BREACH
zranitelnosti: CVE-2013-3587 CWE-310
OK {
not vulnerable, no gzip/deflate/compress/br HTTP compression  - only supplied '/' tested
}
POODLE_SSL
zranitelnosti: CVE-2014-3566 CWE-310
OK {
not vulnerable, no SSLv3
}
fallback_SCSV OK {
no protocol below TLS 1.2 offered
}
SWEET32 OK {
not vulnerable
}
FREAK
zranitelnosti: CVE-2015-0204 CWE-310
OK {
not vulnerable
}
DROWN OK {
not vulnerable on this host and port
}
DROWN_hint INFO {
Make sure you don't use this certificate elsewhere with SSLv2 enabled services, see https://censys.io/ipv4?q=24A01750DA39CC17A1C9596BDF5D39424227F8DB025545184D48711C1FC71FEE
}
LOGJAM
zranitelnosti: CVE-2015-4000 CWE-310
OK {
not vulnerable, no DH EXPORT ciphers,
}
LOGJAM-common_primes
zranitelnosti: CVE-2015-4000 CWE-310
OK {
no DH key with <= TLS 1.2
}
BEAST
zranitelnosti: CVE-2011-3389 CWE-20
OK {
not vulnerable, no SSL3 or TLS1
}
LUCKY13
zranitelnosti: CVE-2013-0169 CWE-310
OK {
not vulnerable
}
winshock
zranitelnosti: CVE-2014-6321 CWE-94
OK {
not vulnerable
}
RC4 OK {
not vulnerable
}
clientsimulation-android_442 INFO {
TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
}
clientsimulation-android_500 INFO {
TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256
}
clientsimulation-android_60 INFO {
TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256
}
clientsimulation-android_70 INFO {
TLSv1.2 ECDHE-RSA-CHACHA20-POLY1305
}
clientsimulation-android_81 INFO {
TLSv1.2 ECDHE-RSA-CHACHA20-POLY1305
}
clientsimulation-android_90 INFO {
TLSv1.3 TLS_CHACHA20_POLY1305_SHA256
}
clientsimulation-android_X INFO {
TLSv1.3 TLS_CHACHA20_POLY1305_SHA256
}
clientsimulation-chrome_74_win10 INFO {
TLSv1.3 TLS_CHACHA20_POLY1305_SHA256
}
clientsimulation-chrome_79_win10 INFO {
TLSv1.3 TLS_CHACHA20_POLY1305_SHA256
}
clientsimulation-firefox_66_win81 INFO {
TLSv1.3 TLS_CHACHA20_POLY1305_SHA256
}
clientsimulation-firefox_71_win10 INFO {
TLSv1.3 TLS_CHACHA20_POLY1305_SHA256
}
clientsimulation-ie_6_xp INFO {
No connection
}
clientsimulation-ie_8_win7 INFO {
No connection
}
clientsimulation-ie_8_xp INFO {
No connection
}
clientsimulation-ie_11_win7 INFO {
No connection
}
clientsimulation-ie_11_win81 INFO {
No connection
}
clientsimulation-ie_11_winphone81 INFO {
No connection
}
clientsimulation-ie_11_win10 INFO {
TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
}
clientsimulation-edge_15_win10 INFO {
TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
}
clientsimulation-edge_17_win10 INFO {
TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
}
clientsimulation-opera_66_win10 INFO {
TLSv1.3 TLS_CHACHA20_POLY1305_SHA256
}
clientsimulation-safari_9_ios9 INFO {
TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
}
clientsimulation-safari_9_osx1011 INFO {
TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
}
clientsimulation-safari_10_osx1012 INFO {
TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
}
clientsimulation-safari_121_ios_122 INFO {
TLSv1.3 TLS_CHACHA20_POLY1305_SHA256
}
clientsimulation-safari_130_osx_10146 INFO {
TLSv1.3 TLS_CHACHA20_POLY1305_SHA256
}
clientsimulation-apple_ats_9_ios9 INFO {
TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
}
clientsimulation-java_6u45 INFO {
No connection
}
clientsimulation-java_7u25 INFO {
No connection
}
clientsimulation-java_8u161 INFO {
TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
}
clientsimulation-java1102 INFO {
TLSv1.3 TLS_AES_256_GCM_SHA384
}
clientsimulation-java1201 INFO {
TLSv1.3 TLS_CHACHA20_POLY1305_SHA256
}
clientsimulation-openssl_102e INFO {
TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
}
clientsimulation-openssl_110l INFO {
TLSv1.2 ECDHE-RSA-CHACHA20-POLY1305
}
clientsimulation-openssl_111d INFO {
TLSv1.3 TLS_CHACHA20_POLY1305_SHA256
}
clientsimulation-thunderbird_68_3_1 INFO {
TLSv1.3 TLS_CHACHA20_POLY1305_SHA256
}
rating_spec INFO {
SSL Labs's 'SSL Server Rating Guide' (version 2009q from 2020-01-30)
}
rating_doc INFO {
https://github.com/ssllabs/research/wiki/SSL-Server-Rating-Guide
}
protocol_support_score INFO {
100
}
protocol_support_score_weighted INFO {
30
}
key_exchange_score INFO {
90
}
key_exchange_score_weighted INFO {
27
}
cipher_strength_score INFO {
90
}
cipher_strength_score_weighted INFO {
36
}
final_score INFO {
93
}
overall_grade OK {
A
}
grade_cap_reason_1 INFO {
Grade capped to A. HSTS is not offered
}
scanTime INFO {
460
}