Some explanatory notes for the information below. As sites can support any combination of plain HTTP (insecure), TLSv1.0 (weak), TLSv1.2 (best), TLSv1.3 (newest), there is quite a patchwork below.
- Website
- The website address, as published by ISO
- Plain HTTP
- How the website responds. Is it still alive?
- Redirect to TLS
- Does the website redirect you away to a TLS website?
- TLSv1.0
- Is the TLSv1.0 protocol enabled? It's going away.
- TLSv1.2
- Is the TLSv1.2 protocol enabled? It's the current state of the art. This must be true.
- TLSv1.3
- Is the TLSv1.3 protocol enabled? It's brand new so not widely available. Aim high!
- SHA-1 Sig
- Practical SHA-1 collisions have been demonstrated. Get your certificate re-issued with a SHA-256 signature instead.