SSL Certificate

Domain
CN = chrisbmn.com
Issuer
C = US, O = Let's Encrypt, CN = YE2
Valid From
August 16, 2026
Expires
November 14, 2026 82 days remaining
Signature Algorithm
ecdsa-with-SHA384
Serial Number
06d91f1d54f74e43809fee53708d33478d04

Certificate data fetched live from chrisbmn.com on page load. Issued by Let's Encrypt - renewed automatically via cPanel's AutoSSL.

Transport Configuration

TLS 1.3 Modern TLS - fastest handshake, forward secrecy by design.
TLS 1.2 Required for legacy client compatibility; still considered secure.
TLS 1.1 Disabled - deprecated, no longer considered secure.
TLS 1.0 Disabled - deprecated, PCI DSS non-compliant since 2018.
HTTP/2 Multiplexed connections, header compression, server push.
HTTPS redirect All HTTP requests are 301-redirected to HTTPS via mod_rewrite.
HSTS max-age=31536000; includeSubDomains; preload - browsers enforce HTTPS for 1 year.
Certificate auto-renewal Let's Encrypt via cPanel AutoSSL - renews before expiry automatically.

TLS protocol and cipher configuration is managed at the hosting level (LiteSpeed / cPanel). Verify independently with SSL Labs.

External Verification

SSL Labs

Qualys SSL Labs - detailed protocol, cipher suite, and certificate chain analysis. The authoritative TLS grading tool.

Scans and grades all HTTP security response headers. See the headers breakdown for the full documented explanation.

Mozilla Observatory

Mozilla's web security scanner - covers headers, cookies, CORS, CSP, and subresource integrity in one report.

← HTTP Security Headers Security Disclosure Policy →