yandex.ru
tested 4 years ago

Certificate Overview

Valid Host NamesMatched*.xn--d1acpjx3f.xn--p1ai
yandex.net
yandex.tj
yandex.com
yandex.com.ua
yandex.org
*.yandex.fr
yandex.ru
*.yandex.uz
yandex.jobs
yandex.com.ru
yandex.uz
*.yandex.kg
yandex.az
yandex.com.tr
*.yandex.md
yandex.co.il
yandex.aero
*.yandex.tj
*.yandex.com.tr
*.yandex.com.am
*.yandex.com.ru
*.yandex.com
*.yandex.ru
yandex.com.ge
yandex.ee
yandex.lv
yandex.lt
*.yandex.com.ua
*.yandex.co.il
*.yandex.az
yandex.by
yandex.ua
yandex.tm
*.yandex.lv
*.ya.ru
*.yandex.lt
yandex.de
*.yandex.ua
*.yandex.ee
yandex.kz
*.yandex.by
*.yandex.aero
*.yandex.net
*.yandex.tm
ya.ru
yandex.com.am
yandex.md
*.yandex.org
*.yandex.kz
yandex.fr
yandex.kg
xn--d1acpjx3f.xn--p1ai
*.yandex.de
*.yandex.com.ge
*.yandex.jobs
Expiresin 2 monthsValid after Oct 1, 2020
TrustTrustedThe certificate was issued by Yandex CA

 

Security

Encryption CiphersWeakWeak encryption ciphers are supported. These are deprecated, and their removal will offer increased security.
Public Key Size256 bitsKey sizes 1024 bits or larger are considered secure. Be aware that unnecessarily large key sizes will slow down the connection establishment.
Secure RenegotiationYes
ProtocolsTLSv1, TLSv1.1, TLSv1.2, TLSv1.3Server supports TLSv1 and / or TLSv1.1. These are deprecated protocols and should be phased out where possible.

 

Performance

HTTP KeepaliveNoEnabling HTTP Keep-Alive will allow subsequent requests to be served faster, without the need to establish a new SSL/TLS connection.
SSL Handshake Size5442 bytesThe amount of data exchanged to establish a session with this server is large. This will result in a slower initial connection.

Using a certificate with fewer intermediate chains and / or a smaller public key size can reduce the amount of data.

 

Encryption Ciphers

CipherStrengthAlgoKeyKeyExHandshake
TLS_AES_256_GCM_SHA384TLSv1.3HighAESGCM256-bitany293ms5322 bytes
TLS_CHACHA20_POLY1305_SHA256TLSv1.3HighCHACHA20/POLY1305256-bitany301ms5290 bytes
TLS_AES_128_GCM_SHA256TLSv1.3HighAESGCM128-bitany298ms5290 bytes
ECDHE-ECDSA-AES256-GCM-SHA384TLSv1.2HighAESGCM256-bitECDH419ms5332 bytes
ECDHE-RSA-AES256-GCM-SHA384TLSv1.2HighAESGCM256-bitECDH382ms5709 bytes
ECDHE-ECDSA-CHACHA20-POLY1305TLSv1.2HighCHACHA20/POLY1305256-bitECDH420ms5315 bytes
ECDHE-RSA-CHACHA20-POLY1305TLSv1.2HighCHACHA20/POLY1305256-bitECDH420ms5693 bytes
ECDHE-ECDSA-AES128-GCM-SHA256TLSv1.2HighAESGCM128-bitECDH381ms5330 bytes
ECDHE-RSA-AES128-GCM-SHA256TLSv1.2HighAESGCM128-bitECDH430ms5709 bytes
ECDHE-ECDSA-AES128-CCM8TLSv1.2HighAESCCM8128-bitECDH423ms5316 bytes
ECDHE-ECDSA-AES128-CCMTLSv1.2HighAESCCM128-bitECDH429ms5331 bytes
ECDHE-ECDSA-AES128-SHA256TLSv1.2HighAES128-bitECDH380ms5415 bytes
ECDHE-RSA-AES128-SHA256TLSv1.2HighAES128-bitECDH415ms5793 bytes
ECDHE-RSA-AES128-SHATLSv1HighAES128-bitECDH415ms5683 bytes
AES128-GCM-SHA256TLSv1.2HighAESGCM128-bitRSA381ms5597 bytes
AES128-CCM8TLSv1.2HighAESCCM8128-bitRSA414ms5581 bytes
AES128-CCMTLSv1.2HighAESCCM128-bitRSA417ms5597 bytes
AES128-SHA256TLSv1.2HighAES128-bitRSA404ms5681 bytes
DES-CBC3-SHASSLv3Low3DES168-bitRSA282ms5533 bytes