IM Observatory server report for it.ibm.com

Test started 2022-04-13 15:09:01 UTC .

Show client to server result | Permalink to this report |

nxpfs.ucfederationcloud.com:5269
Certificate is not trusted, grade capped to F. Ignoring trust: B.
Server uses Diffie-Hellman parameters of < 2048 bits. Grade capped to B.
nxpfs.ucfederationcloud.com:5269
StartTLS
ALLOWED

SRV records _xmpp-server._tcp.it.ibm.com NO DNSSEC

Priority Weight Port Server
0 20 5269 nxpfs.ucfederationcloud.com

TLSA records

Certificates

Subject
commonName
nxpfs.ucfederationcloud.com
countryName
US
localityName
Sunnyvale
organizationName
NextPlane Inc
stateOrProvinceName
California
Details
Signature algorithm
sha256WithRSAEncryption
Public key
2048 bit RSA
Valid from
2021-10-26 20:03:38 UTC
Valid to
2022-10-09 20:03:38 UTC
CRL
http://crl.entrust.net/level1k.crl
OCSP
http://ocsp.entrust.net
Valid for it.ibm.com
NO
5A:A7:E3:9A:33:10:63:6C:65:4D:AF:03:CF:18:0D:74:C9:AA:D4:06
Subject Alternative Names
DNSName
nxpfs.ucfederationcloud.com
DNSName
Praintl.com
DNSName
Prahs.com
DNSName
test.ucapps.net
Subject
commonName
Entrust Certification Authority - L1K
countryName
US
organizationalUnitName
(c) 2012 Entrust, Inc. - for authorized use only
organizationalUnitName
See www.entrust.net/legal-terms
organizationName
Entrust, Inc.
Details
Signature algorithm
sha256WithRSAEncryption
Public key
2048 bit RSA
Valid from
2015-10-05 19:13:56 UTC
Valid to
2030-12-05 19:43:56 UTC
CRL
http://crl.entrust.net/g2ca.crl
OCSP
http://ocsp.entrust.net
F2:1C:12:F4:6C:DB:6B:2E:16:F0:9F:94:19:CD:FF:32:84:37:B2:D7
Subject
commonName
Entrust Root Certification Authority - G2
countryName
US
organizationalUnitName
(c) 2009 Entrust, Inc. - for authorized use only
organizationalUnitName
See www.entrust.net/legal-terms
organizationName
Entrust, Inc.
Details
Signature algorithm
sha256WithRSAEncryption
Public key
2048 bit RSA
Valid from
2009-07-07 17:25:54 UTC
Valid to
2030-12-07 17:55:54 UTC
8C:F4:27:FD:79:0C:3A:D1:66:06:8D:E8:1E:57:EF:BB:93:22:72:D4

Protocols

SSLv2 No
SSLv3 No
TLSv1 Yes
TLSv1.1 Yes
TLSv1.2 Yes

Ciphers

Server does respect the client's cipher ordering.

Cipher suiteBitsizeForward secrecyInfo
ECDHE-RSA-AES256-GCM-SHA384 (0xc030) 256 Yes Curve: sect571r1
ECDHE-RSA-AES256-SHA384 (0xc028) 256 Yes Curve: sect571r1
ECDHE-RSA-AES256-SHA (0xc014) 256 Yes Curve: sect571r1
DHE-RSA-AES256-GCM-SHA384 (0x9f) 256 Yes Diffie-Hellman:
Group: RFC 2409 First Oakley Default Group
Bitsize: 1024
DHE-RSA-AES256-SHA256 (0x6b) 256 Yes Diffie-Hellman:
Group: RFC 2409 First Oakley Default Group
Bitsize: 1024
DHE-RSA-AES256-SHA (0x39) 256 Yes Diffie-Hellman:
Group: RFC 2409 First Oakley Default Group
Bitsize: 1024
AES256-GCM-SHA384 (0x9d) 256 No -
AES256-SHA256 (0x3d) 256 No -
AES256-SHA (0x35) 256 No -
ECDHE-RSA-AES128-GCM-SHA256 (0xc02f) 128 Yes Curve: sect571r1
ECDHE-RSA-AES128-SHA256 (0xc027) 128 Yes Curve: sect571r1
ECDHE-RSA-AES128-SHA (0xc013) 128 Yes Curve: sect571r1
DHE-RSA-AES128-GCM-SHA256 (0x9e) 128 Yes Diffie-Hellman:
Group: RFC 2409 First Oakley Default Group
Bitsize: 1024
DHE-RSA-AES128-SHA256 (0x67) 128 Yes Diffie-Hellman:
Group: RFC 2409 First Oakley Default Group
Bitsize: 1024
DHE-RSA-AES128-SHA (0x33) 128 Yes Diffie-Hellman:
Group: RFC 2409 First Oakley Default Group
Bitsize: 1024
AES128-GCM-SHA256 (0x9c) 128 No -
AES128-SHA256 (0x3c) 128 No -
AES128-SHA (0x2f) 128 No -
ECDHE-RSA-DES-CBC3-SHA (0xc012) WEAK 112 Yes Curve: sect571r1
EDH-RSA-DES-CBC3-SHA (0x16) WEAK 112 Yes Diffie-Hellman:
Group: RFC 2409 First Oakley Default Group
Bitsize: 1024
DES-CBC3-SHA (0xa) WEAK 112 No -

Badge

xmpp.net score

Want to show this result on your webpage? Add this:

<a href='https://xmpp.net/result.php?domain=it.ibm.com&amp;type=server'><img src='https://xmpp.net/badge.php?domain=it.ibm.com' alt='xmpp.net score' /></a>