See this report on

Thank you,

Grade: C.

That is pretty uninformative.  Did I miss something?
I'm not sure why the direct link isn't working, but if you click on the "" heading it will take you through to the detailed report.


* This server supports weak Diffie-Hellman (DH) key exchange parameters. Grade capped to B.
* Certificate has a weak signature and expires after 2015. Upgrade to SHA2 to avoid browser warnings.
* The server supports only older protocols, but not the current best TLS 1.2. Grade capped to C.
* The server does not support Forward Secrecy with the reference browsers.

Of those, only the SHA1 signature is related to the cert itself - the rest have to do with Upfront's server configuration.
Well, we can edit the apache server config too.  In fact, I thought I'd done the diffie-hellman fix, but I guess I didn't.

I don't understand the 'cert expires' part, it was renewed in September of 2015.

Is there any reason we couldn't use letsencrypt for bugs?
