SSL/TLS Server Information

Starting report generation at Fri May 24 21:58:37 CEST 2013

Resolving hostname...
IP address for server is 64.4.11.42

Connecting to www.microsoft.com:443...
TCP connection established.

Starting SSLv3/TLS handshake...

ssl_debug(400): Starting handshake (iSaSiLk 4.4 Evaluation Version)...
ssl_debug(400): Sending v3 client_hello message to www.microsoft.com:443, requesting version 3.2...
ssl_debug(400): Sending extensions: elliptic_curves (10), renegotiation_info (65281), ec_point_formats (11)
ssl_debug(400): Received v3 server_hello handshake message.
ssl_debug(400): Server selected SSL version 3.1.
ssl_debug(400): Server created new session 90:92:98:06:4D:BC:76:A7...
ssl_debug(400): CipherSuite selected by server: SSL_RSA_WITH_RC4_128_MD5
ssl_debug(400): CompressionMethod selected by server: NULL
ssl_debug(400): Server does not supports secure renegotiation.
ssl_debug(400): Received certificate handshake message with server certificate.
ssl_debug(400): Server sent a 2048 bit RSA certificate, chain has 4 elements.
ssl_debug(400): Received server_hello_done handshake message.
ssl_debug(400): Sending client_key_exchange handshake...
ssl_debug(400): Sending change_cipher_spec message...
ssl_debug(400): Sending finished message...
ssl_debug(400): Received change_cipher_spec message.
ssl_debug(400): Received finished message.
ssl_debug(400): Handshake completed, statistics:
ssl_debug(400): Read 5525 bytes in 3 records, wrote 577 bytes in 4 records.
SSL/TLS connect successful.

Checking for TLS 1.1 support...
TLS 1.1 is NOT supported by this server.

Checking for TLS 1.0 support...
TLS 1.0 is supported by this server.

Checking for SSLv3 support...
SSLv3 is supported by this server.

Checking for SSLv2 support...
SSLv2 is NOT supported by this server.

Server name returned in HTTP request:
Microsoft-IIS/8.0

SSLv2 Summary

SSL 2.0 is not supported by this server.

SSLv3/TLS Summary

Checking server supported SSLv3/TLS ciphersuites (this may take a while)...

SSL_RSA_WITH_RC4_128_MD5
SSL_RSA_WITH_RC4_128_SHA
SSL_RSA_WITH_3DES_EDE_CBC_SHA
TLS_RSA_WITH_AES_256_CBC_SHA
TLS_RSA_WITH_AES_128_CBC_SHA

SSLv3/TLS ciphersuites NOT supported or not enabled by this server:

TLS_DHE_DSS_WITH_AES_256_CBC_SHA
TLS_DHE_RSA_WITH_AES_256_CBC_SHA
TLS_RSA_WITH_CAMELLIA_256_CBC_SHA
TLS_DHE_DSS_WITH_CAMELLIA_256_CBC_SHA
TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA
TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA
TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA
TLS_ECDH_RSA_WITH_AES_256_CBC_SHA
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
TLS_DH_DSS_WITH_AES_256_CBC_SHA
TLS_DH_RSA_WITH_AES_256_CBC_SHA
TLS_DH_DSS_WITH_CAMELLIA_256_CBC_SHA
TLS_DH_RSA_WITH_CAMELLIA_256_CBC_SHA
TLS_RSA_PSK_WITH_AES_256_CBC_SHA
TLS_DHE_PSK_WITH_AES_256_CBC_SHA
TLS_PSK_WITH_AES_256_CBC_SHA
SSL_DHE_DSS_WITH_3DES_EDE_CBC_SHA
SSL_DHE_RSA_WITH_3DES_EDE_CBC_SHA
TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA
TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA
TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA
TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA
SSL_DH_DSS_WITH_3DES_EDE_CBC_SHA
SSL_DH_RSA_WITH_3DES_EDE_CBC_SHA
TLS_RSA_PSK_WITH_3DES_EDE_CBC_SHA
TLS_DHE_PSK_WITH_3DES_EDE_CBC_SHA
TLS_PSK_WITH_3DES_EDE_CBC_SHA
SSL_RSA_WITH_IDEA_CBC_SHA
SSL_DHE_DSS_WITH_RC4_128_SHA
TLS_DHE_DSS_WITH_AES_128_CBC_SHA
TLS_DHE_RSA_WITH_AES_128_CBC_SHA
TLS_RSA_WITH_CAMELLIA_128_CBC_SHA
TLS_DHE_DSS_WITH_CAMELLIA_128_CBC_SHA
TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA
TLS_ECDH_ECDSA_WITH_RC4_128_SHA
TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA
TLS_ECDHE_ECDSA_WITH_RC4_128_SHA
TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA
TLS_ECDH_RSA_WITH_RC4_128_SHA
TLS_ECDH_RSA_WITH_AES_128_CBC_SHA
TLS_ECDHE_RSA_WITH_RC4_128_SHA
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
TLS_DH_DSS_WITH_AES_128_CBC_SHA
TLS_DH_RSA_WITH_AES_128_CBC_SHA
TLS_DH_DSS_WITH_CAMELLIA_128_CBC_SHA
TLS_DH_RSA_WITH_CAMELLIA_128_CBC_SHA
TLS_RSA_PSK_WITH_AES_128_CBC_SHA
TLS_RSA_PSK_WITH_RC4_128_SHA
TLS_DHE_PSK_WITH_AES_128_CBC_SHA
TLS_DHE_PSK_WITH_RC4_128_SHA
TLS_PSK_WITH_RC4_128_SHA
TLS_PSK_WITH_AES_128_CBC_SHA
SSL_RSA_WITH_DES_CBC_SHA
SSL_DHE_DSS_WITH_DES_CBC_SHA
SSL_DHE_RSA_WITH_DES_CBC_SHA
SSL_DH_DSS_WITH_DES_CBC_SHA
SSL_DH_RSA_WITH_DES_CBC_SHA
SSL_RSA_EXPORT1024_WITH_DES_CBC_SHA
SSL_DHE_DSS_EXPORT1024_WITH_DES_CBC_SHA
SSL_RSA_EXPORT1024_WITH_RC4_56_SHA
SSL_DHE_DSS_EXPORT1024_WITH_RC4_56_SHA
SSL_RSA_EXPORT_WITH_DES40_CBC_SHA
SSL_DHE_DSS_EXPORT_WITH_DES40_CBC_SHA
SSL_DHE_RSA_EXPORT_WITH_DES40_CBC_SHA
SSL_DH_DSS_EXPORT_WITH_DES40_CBC_SHA
SSL_DH_RSA_EXPORT_WITH_DES40_CBC_SHA
SSL_RSA_EXPORT_WITH_RC4_40_MD5
SSL_RSA_EXPORT_WITH_RC2_CBC_40_MD5
TLS_ECDH_anon_WITH_AES_256_CBC_SHA
TLS_DH_anon_WITH_AES_256_CBC_SHA
TLS_DH_anon_WITH_CAMELLIA_256_CBC_SHA
TLS_ECDH_anon_WITH_3DES_EDE_CBC_SHA
SSL_DH_anon_WITH_3DES_EDE_CBC_SHA
TLS_ECDH_anon_WITH_RC4_128_SHA
TLS_ECDH_anon_WITH_AES_128_CBC_SHA
TLS_DH_anon_WITH_AES_128_CBC_SHA
TLS_DH_anon_WITH_CAMELLIA_128_CBC_SHA
SSL_DH_anon_WITH_RC4_128_MD5
SSL_DH_anon_WITH_DES_CBC_SHA
SSL_DH_anon_EXPORT_WITH_DES40_CBC_SHA
SSL_DH_anon_EXPORT_WITH_RC4_40_MD5
SSL_RSA_WITH_NULL_SHA
TLS_ECDH_ECDSA_WITH_NULL_SHA
TLS_ECDHE_ECDSA_WITH_NULL_SHA
TLS_ECDH_RSA_WITH_NULL_SHA
TLS_ECDHE_RSA_WITH_NULL_SHA
TLS_ECDH_anon_WITH_NULL_SHA
TLS_RSA_PSK_WITH_NULL_SHA
TLS_DHE_PSK_WITH_NULL_SHA
TLS_PSK_WITH_NULL_SHA
SSL_RSA_WITH_NULL_MD5

Supported cipher algorithms

Algorithm NameSupported
AES yes
Camellia no
DES no
DESede yes
IDEA no
NULL no
RC2 no
RC4 yes

Supported key exchange algorithms

Algorithm NameSupported
DHE_DSS no
DHE_DSS_EXPORT no
DHE_DSS_EXPORT1024 no
DHE_PSK no
DHE_RSA no
DHE_RSA_EXPORT no
DH_DSS no
DH_DSS_EXPORT no
DH_RSA no
DH_RSA_EXPORT no
DH_anon no
DH_anon_EXPORT no
ECDHE_ECDSA no
ECDHE_RSA no
ECDH_ECDSA no
ECDH_RSA no
ECDH_anon no
PSK no
RSA yes
RSA_EXPORT no
RSA_EXPORT1024 no
RSA_PSK no

RSA Certificate Chain

Certificate 0

Version 3
Serial Number 0x18e0b8b40001000031d1
Signature Algorithm SHA/RSA
Subject CN = www.microsoft.com
= Microsoft Corporation
OU = MSCOM
ST = WA
= US
= Redmond
Valid Not Before Sat Jan 12 01:07:41 CET 2013
Not After Mon Jan 12 01:07:41 CET 2015
Issuer CN = MSIT Machine Auth CA 2
DC = com
DC = microsoft
DC = corp
DC = redmond
Public Key Algorithm RSA
Key length2048 bit
Modulus  2015171730954188851242410669855711355127
 6299770613991370957556929854402490133363
 5035577462845840830253382193088007332867
 1479058848177683925255571965607891180149
 5420227174713720909914081360774368478150
 1252208936091287420847563249448176721050
 8047575693293545158951908395316276731570
 2034021923951658450694562000857006068956
 2486443485332979903899895107374512993395
 4685789758259712457291724419142494354504
 7863745559514980901646828554825188023023
 2880361972827376858309925909439033049840
 1816989927127608137924356146211675424487
 2787849176898647309105361105927147649458
 4390193275861371778345088351610075218218
 98647731881886463
Public Exponent  65537
Extension 1 KeyUsage:
digitalSignature | keyEncipherment | dataEncipherment
Extension 2 SubjectKeyIdentifier:
2B:DB:4A:3F:90:02:48:9E:0F:89:21:E2:EB:4A:73:1E:E0:0F:85:6B
Extension 3 CRLDistributionPoints:
DistributionPoint: uniformResourceIdentifier: http://mscrl.m
icrosoft.com/pki/mscorp/crl/MSIT%20Machine%20Auth%20CA%202(1
).crl
uniformResourceIdentifier: http://crl.microsoft.com/pki/msco
rp/crl/MSIT%20Machine%20Auth%20CA%202(1).crl
uniformResourceIdentifier: http://corppki/crl/MSIT%20Machine
%20Auth%20CA%202(1).crl
Extension 4 1.3.6.1.4.1.311.21.10:
UnknownExtension:     OBJECT ID = 1.3.6.1.4.1.311.21.10
SEQUENCE[C] = 2 elements
Extension 5 AuthorityInfoAccess:
accessMethod: OBJECT ID = caIssuers
accessLocation: uniformResourceIdentifier: http://www.micros
oft.com/pki/mscorp/MSIT%20Machine%20Auth%20CA%202(1).crt
accessMethod: OBJECT ID = caIssuers
accessLocation: uniformResourceIdentifier: http://corppki/ai
a/MSIT%20Machine%20Auth%20CA%202(1).crt
Extension 6 symmetricCapabilities:
This SMIMECapabilities contains 8 capabilities:
RC2-CBC, ARCFOUR, AES256-CBC, CMS-AES256-Wrap, AES128-CBC, C
MS-AES128-Wrap, DES-CBC, DES-EDE3-CBC
Extension 7 1.3.6.1.4.1.311.21.7:
UnknownExtension:     OBJECT ID = 1.3.6.1.4.1.311.21.7
SEQUENCE[C] = 3 elements
Extension 8 ExtendedKeyUsage:
KeyPurposeId 0:  TLS Web client authentication
KeyPurposeId 1:  TLS Web server authentication
Extension 9 AuthorityKeyIdentifier:
KeyIdentifier: EB:DB:11:5E:F8:09:9E:D8:D6:62:9C:FD:62:9D:E3:
84:4A:28:E1:27

Certificate 1

Version 3
Serial Number 0x615daad2000600000040
Signature Algorithm SHA/RSA
Subject CN = MSIT Machine Auth CA 2
DC = com
DC = microsoft
DC = corp
DC = redmond
Valid Not Before Tue May 15 22:40:55 CEST 2012
Not After Sun May 15 22:50:55 CEST 2016
Issuer CN = Microsoft Internet Authority
Public Key Algorithm RSA
Key length2048 bit
Modulus  2395811020978788151877210355462272128311
 6793107328720228466371367071156720896696
 7115470393443724154303963602454475063857
 9356710115288672539740155074108980061615
 1461393251953204010353495780498510784083
 1635722920928525071926716278658300838807
 6215903002652655882068656971652031864313
 9835115554667568438580337303817290840461
 3206113774959701886237370996646030614378
 6091145499381441173164105685899455935767
 4633449152466551410477800645900022723668
 8573718760928318824058339666079932326450
 8736695957051624664868706699965432696042
 8043609551980443408538123124709442034456
 5184312684107900874499466710883772084908
 25929601917099031
Public Exponent  65537
Extension 1 BasicConstraints:
CA: yes
PathLenConstraint: 0
Extension 2 KeyUsage:
digitalSignature | keyCertSign | cRLSign
Extension 3 1.3.6.1.4.1.311.21.2:
UnknownExtension:     OBJECT ID = 1.3.6.1.4.1.311.21.2
OCTET STRING = 20 bytes: 23:B7:D0:ED:68...
Extension 4 1.3.6.1.4.1.311.20.2:
UnknownExtension:     OBJECT ID = 1.3.6.1.4.1.311.20.2
BMPString = "SubCA"
Extension 5 SubjectKeyIdentifier:
EB:DB:11:5E:F8:09:9E:D8:D6:62:9C:FD:62:9D:E3:84:4A:28:E1:27
Extension 6 1.3.6.1.4.1.311.21.1:
UnknownExtension:     OBJECT ID = 1.3.6.1.4.1.311.21.1
INTEGER = 65537
Extension 7 CRLDistributionPoints:
DistributionPoint: uniformResourceIdentifier: http://mscrl.m
icrosoft.com/pki/mscorp/crl/mswww(6).crl
uniformResourceIdentifier: http://crl.microsoft.com/pki/msco
rp/crl/mswww(6).crl
uniformResourceIdentifier: http://corppki/crl/mswww(6).crl
Extension 8 AuthorityInfoAccess:
accessMethod: OBJECT ID = caIssuers
accessLocation: uniformResourceIdentifier: http://www.micros
oft.com/pki/mscorp/mswww(6).crt
accessMethod: OBJECT ID = caIssuers
accessLocation: uniformResourceIdentifier: http://corppki/ai
a/mswww(6).crt
Extension 9 AuthorityKeyIdentifier:
KeyIdentifier: 2A:4D:97:95:5D:34:7E:9D:B6:E6:33:BE:9C:27:C1:
70:7E:67:DB:C1

Certificate 2

Version 3
Serial Number 0x7276fae
Signature Algorithm SHA/RSA
Subject CN = Microsoft Internet Authority
Valid Not Before Wed Apr 25 19:41:36 CEST 2012
Not After Sat Apr 25 19:40:55 CEST 2020
Issuer CN = Baltimore CyberTrust Root
= Baltimore
OU = CyberTrust
= IE
Public Key Algorithm RSA
Key length4096 bit
Modulus  7761575172722499392682044754322079737153
 3992871725528315970222271528682316829297
 4003663835551078883367676939841564154798
 3714556093210808813406285538667154091295
 0326311278616546621900142293244781968685
 9072092815433702764428942283491057834987
 8090027249313982167014575358169982303814
 8864009165889428969694457235760851460224
 4790301172382297040497539025786196282761
 4119701791608665022619001817818823455853
 8223998888504894281757577442154592315953
 2102569022126899337574794335022381219483
 1411060459434590700623302145051971951369
 0910806808224900268707820933875566951049
 6946346077482471547657798389211680845184
 9782341447813067088735688038453275018663
 0996359558023443007280702445669146050034
 2250221913014491946862301289133176338149
 6199146720615498453407505528566394685413
 0713325369225110314118600710054673538474
 8305847055476042489596841627805197138213
 4070131443837766710525424623727260083866
 6677300738915780967132266606452926487305
 8651635915189248855740901977491615407082
 7262728981275026450905125846959356624373
 2181575384720735202237066926915733679782
 9617113703176974977426403314097349803975
 1977192209535341933771458815891847385765
 5632965242263877593407557198426269710824
 7107497637055898586138947406072207715054
 350865886507631515856436920060957
Public Exponent  65537
Extension 1 KeyUsage:
digitalSignature | keyCertSign | cRLSign
Extension 2 BasicConstraints:
CA: yes
PathLenConstraint: 1
Extension 3 SubjectKeyIdentifier:
2A:4D:97:95:5D:34:7E:9D:B6:E6:33:BE:9C:27:C1:70:7E:67:DB:C1
Extension 4 CertificatePolicies:
certificatePolicy[0]: policyIdentifier: 1.3.6.1.4.1.6334.1.0
policyQualifiers[0]: policyQualifierId: id-pkix-cps
CPS URI: http://cybertrust.omniroot.com/repository.cfm
Extension 5 CRLDistributionPoints:
DistributionPoint: uniformResourceIdentifier: http://cdp1.pu
blic-trust.com/CRL/Omniroot2025.crl
Extension 6 AuthorityKeyIdentifier:
KeyIdentifier: E5:9D:59:30:82:47:58:CC:AC:FA:08:54:36:86:7B:
3A:B5:04:4D:F0

Certificate 3

Version 3
Serial Number 0x20000b9
Signature Algorithm SHA/RSA
Subject CN = Baltimore CyberTrust Root
= Baltimore
OU = CyberTrust
= IE
Valid Not Before Fri May 12 20:46:00 CEST 2000
Not After Tue May 13 01:59:00 CEST 2025
Issuer CN = Baltimore CyberTrust Root
= Baltimore
OU = CyberTrust
= IE
Public Key Algorithm RSA
Key length2048 bit
Modulus  2057917665142116798710647171888818630953
 4186253587759121109122482694167416584428
 9202956782160358224494516395810237651229
 9408900882631402984365480710880373972956
 5431642116323937940944378450034252354609
 0205362861758633241562190630389274099330
 7068872735667602721635953259350436611927
 2034244698731524943132462329205729047681
 9977154552401488275236517064298547574226
 2411780586312152049430765527142698607891
 7217383478420381375139154341613794371303
 6822325833163936016200346380441867822521
 9543834530945571463750827689206135535778
 5328168602107026282695945834955006612147
 3503159372042565637207943001239485986699
 13435346712336953
Public Exponent  65537
Extension 1 KeyUsage:
keyCertSign | cRLSign
Extension 2 BasicConstraints:
CA: yes
PathLenConstraint: 3
Extension 3 SubjectKeyIdentifier:
E5:9D:59:30:82:47:58:CC:AC:FA:08:54:36:86:7B:3A:B5:04:4D:F0

Back to the server selection page.


Generated by IAIK SSL/TLS ServerInfo using the iSaSiLk and IAIK JCE Java cryptography libraries, (c) 2002 IAIK, (c) 2003 - 2012 SIC. For more information see http://jce.iaik.tugraz..at/ or mailto:jce-sales@iaik.tugraz.at.