2015-02-25 website test - banks: Difference between revisions

From annawiki
No edit summary
No edit summary
Line 19: Line 19:
  Cipher Strength 90
  Cipher Strength 90
  This server supports TLS_FALLBACK_SCSV to prevent protocol downgrade attacks.
  This server supports TLS_FALLBACK_SCSV to prevent protocol downgrade attacks.
===consorsbank.de===
* https://www.ssllabs.com/ssltest/analyze.html?d=consorsbank.de
A
Certificate 100
Protocol Support 95
Key Exchange 90
Cipher Strength 90
Certificate uses a weak signature. When renewing, ensure you upgrade to SHA2.
This server supports TLS_FALLBACK_SCSV to prevent protocol downgrade attacks.
This server supports HTTP Strict Transport Security with long duration.


==B==
==B==

Revision as of 2015-02-25T01:59:49

A

dab-bank.de

A
Certificate 100
Protocol Support 95
Key Exchange 80
Cipher Strength 90
Certificate uses a weak signature. When renewing, ensure you upgrade to SHA2.
This server supports TLS_FALLBACK_SCSV to prevent protocol downgrade attacks.
This server supports HTTP Strict Transport Security with long duration.

banking.netbank.de

A
Certificate 100
Protocol Support 95
Key Exchange 90
Cipher Strength 90
This server supports TLS_FALLBACK_SCSV to prevent protocol downgrade attacks.

consorsbank.de

A
Certificate 100
Protocol Support 95
Key Exchange 90
Cipher Strength 90
Certificate uses a weak signature. When renewing, ensure you upgrade to SHA2.
This server supports TLS_FALLBACK_SCSV to prevent protocol downgrade attacks.
This server supports HTTP Strict Transport Security with long duration.

B

ing-diba.de

B
Certificate 100
Protocol Support 95
Key Exchange 90
Cipher Strength 90
Certificate uses a weak signature. When renewing, ensure you upgrade to SHA2.
This server accepts the RC4 cipher, which is weak. Grade capped to B.
There is no support for secure renegotiation.
The server does not support Forward Secrecy with the reference browsers.
This server supports TLS_FALLBACK_SCSV to prevent protocol downgrade attacks.
This server supports HTTP Strict Transport Security with long duration.

C

banking.postbank.de

C
Certificate 100
Protocol Support 90
Key Exchange 90
Cipher Strength 90
This server is vulnerable to the POODLE attack. If possible, disable SSL 3 to mitigate. Grade capped to C.
Certificate uses a weak signature. When renewing, ensure you upgrade to SHA2.
This server accepts the RC4 cipher, which is weak. Grade capped to B.
The server does not support Forward Secrecy with the reference browsers.
This server supports TLS_FALLBACK_SCSV to prevent protocol downgrade attacks.