Badssl.com (2017)
badssl.com
badssl.com
SHA384 with P-384 is much more common (and tested elsewhere on the site); what is unique about this one is using a larger hash with RSA keys.
Like some of the other certs, it requires partnerships with CAs willing to bend their process a little for the sake of publicly available test infra.
Though on a second thought I'm not sure what you're getting at. Certificate renewal isn't optional. It's valid for however long it's valid.
DNS / Networking:
- http://neverssl.com/ - manually trigger a paywall / login screen on public wifi networks
- https://ifconfig.co - Simplest way to get own IP address, especially from scripts.
Web development:
- http://vcap.me, http://lvh.me - Main domain and all subdomains resolve to localhost.
- http://nip.io - Subdomains resolve to that IP Address, e.g. `127.0.0.1.nip.io`
- https://httpstat.us - simple service to generate desired response codes
- https://badssl.com - test SSL client configuration against many invalid certificates
- https://permission.site/ - test various permission requests
Anyone have any other good candidates?
curl https://httpbin.org/ip
to get your IP address, so no need to remember an additional domain. Although I think everyone knows https://icanhazip.comhttps://www.mail-tester.com/ - fantastic to check your homebrew mailserver for compliance
https://gwhois.org/ - online whois tool, I liked it a lot, but I no longer remember why
https://mxtoolbox.com - a larger collection of online tools, among them a service to check your domain if it's listed on different email spam lists
Well, having whois along with DNS popular records: MX, A, SOA, TXT, NS - is helpful. Thanks.
[1] - https://www.ssllabs.com/ssltest/
[2] - https://dev.ssllabs.com/ssltest/
[3] - https://github.com/drwetter/testssl.sh
[4] - https://securityheaders.com/
[5] - https://urlscan.io/
[6] - https://bgp.he.net/
[7] - https://www.robtex.com/
[8] - https://www.whatsmydns.net/
[9] - https://www.virustotal.com/old-browsers/
[10] - https://www.whoisds.com/
[11] - https://ssl-config.mozilla.org/
[12] - https://crt.sh/
[13] - https://www.thousandeyes.com/outages/ [commercial site but priceless in my opinion]
[14] - https://downdetector.com/
[15] - https://ednscomp.isc.org/ednscomp?zone=ycombinator.com
[16] - https://www.shodan.io/
[17] - https://validator.w3.org/
[18] - https://wigle.net/
BadTLS explicitly exists to test certs that you generally should not, but often do, run into in the wild. As a result, most software handles these in poor ways, with error messages that are unhelpful at best.
Writing tests that utilize a custom root doesn’t seem all that much work for a library supporting TLS.
It's a great way to do baseline sanity checking on any service provider you are using or assessing for use. How well they manage and configure certificate functionality is a good indicator of whether they are on top of things generally.
(also a good way to check up on your own internal IT department as well).
I can imagine the cert providers getting mad at them for having intentionally wrong certificates. Hope they're smarter than that, but if not, this site is well enough done that I think they will stick up for themselves.
Common Name (CN) *.badssl.com Organization (O) <Not Part Of Certificate> Organizational Unit (OU) <Not Part Of Certificate> Common Name (CN) R3 Organization (O) Let's Encrypt Organizational Unit (OU) <Not Part Of Certificate> Issued On Friday, August 12, 2022 at 7:57:46 AM Expires On Thursday, November 10, 2022 at 6:57:45 AM SHA-256 Fingerprint EE 5C E1 DF A7 A5 36 57 C5 45 C6 2B 65 80 2E 42 72 87 8D AB D6 5C 0A AD CF 85 78 3E BB 0B 4D 5C SHA-1 Fingerprint 8C 02 16 86 C6 E3 6C F2 07 94 75 81 D4 D4 C7 2F B5 9E C3 A5