This active scan rule runs once per host and performs HTTPS configuration analysis for sites using HTTPS. It skips HTTP sites entirely.
The rule raises two types of alerts:
Always raised for HTTPS sites. Contains the full HTTPS configuration report including:
Raised when DeepViolet's TLS risk scoring identifies one or more security issues. The alert severity is based on the worst finding:
The alert includes the risk score, letter grade, detailed findings with rule IDs, and the full configuration report.
Latest code: HttpsConfigScanRule.javaThis add-on uses DeepViolet for TLS/SSL analysis. The risk scoring rules and rule IDs are documented in the DeepViolet project.