ConfigurationLive6 checks
SSL/TLS Security Scanner
Verify your SSL/TLS configuration, certificate validity, and encryption strength.
What we check
- Certificate validity window (not expired, not near-expiry) and issuer chain trust
- Hostname match — SAN covers the scanned host
- Supported protocol versions — flags SSLv3/TLS1.0/TLS1.1 if still accepted
- Negotiated cipher strength on a modern client handshake
- HSTS presence, cross-checked with the Security Headers scanner
- HTTP → HTTPS redirect enforced
