HTTPS configuration checker
Catch deprecated protocol versions, missing HSTS and broken HTTP redirects before a compliance scan or a customer does.
How it measures
- One unvalidated handshake per protocol version (TLS 1.0, 1.1, 1.2, 1.3) records what the server accepts; these diagnostic handshakes never influence any monitor.
- A separate validated handshake decides whether the certificate is trusted by a public root store.
- A GET to the HTTPS URL reads Strict-Transport-Security; a GET to the same path on port 80 records whether it redirects to HTTPS.
- HTTP/2 support is read from ALPN negotiation, not from a full HTTP/2 request.
Limits
- Cipher suite strength, OCSP stapling, certificate transparency and key sizes are not graded.
- Checks run against the first resolved address only; load-balanced pools can differ per node.
- The HTTP redirect test only runs for the standard port 443.
- When the certificate is untrusted the HTTPS request is refused by design, so HSTS is reported as unreadable rather than guessed.
Troubleshooting
- TLS 1.0 or 1.1 accepted
- Disable them in the web server or load balancer configuration (for example ssl_protocols TLSv1.2 TLSv1.3 in nginx). Both are deprecated by RFC 8996.
- HSTS missing
- Add Strict-Transport-Security: max-age=31536000; includeSubDomains once every subdomain serves HTTPS. Start with a short max-age if unsure.
- Plain HTTP serves content
- Return a 301 to the HTTPS URL for every request on port 80; otherwise users who type the hostname stay on HTTP.