ssl

July 2016 scan results

This month the scan has a bit more information.

I’ve added special probes to detect whether the server is intolerant to specific types of Client Hello messages.

While support for TLSv1.2 is still not universal (being just under 90%), tolerance to Client Hello messages advertising support for TLSv1.2 is essentially full, with just 67 servers being detected as intolerant to such messages.

Support for more uncommon messages is much worse though, clients sending their maximum supported version set to TLSv1.2 can expect 1.3% of servers rejecting their connections. Higher protocol versions like TLSv1.4 have a rate of rejection on around 2.45%, for very high protocol versions it rises to 3.295% for SSL 3.254 (that would be TLSv1.253).

Clients sending Client Hello with a lot of options or extensions can expect even more intolerance. Sending multiple key shares (from TLSv1.3 draft), most of defined extensions and couple hundred ciphersuites can expect their connections rejected by over 7% of servers. In general intolerance for very big Client Hello messages, like 16KiB and 24KiB large, is respectively at 23.7% and a whopping 89.5%!

If fixing this will follow similar deployment rates as TLSv1.2 or RC4 deprecation, it doesn’t look like we will be able to deploy most Post Quantum key exchanges any time soon…

Besides that, there were no major changes, just continuation of long established trends, so I won’t be doing full analysis for this month too.

SSL/TLS survey of 603391 websites from Alexa's top 1 million
Stats only from connections that did provide valid certificates
(or anonymous DH from servers that do also have valid certificate installed)


Supported Ciphers         Count     Percent
-------------------------+---------+-------
3DES                      532905    88.3184
3DES Only                 550       0.0912
3DES Preferred            1719      0.2849
3DES forced in TLS1.1+    992       0.1644
AES                       599329    99.3268
AES Only                  46610     7.7247
AES-CBC                   598756    99.2318
AES-CBC Only              4850      0.8038
AES-GCM                   509780    84.4858
AES-GCM Only              526       0.0872
CAMELLIA                  267705    44.3668
CAMELLIA Only             1         0.0002
CHACHA20                  83982     13.9183
CHACHA20 Only             3         0.0005
Insecure                  53186     8.8145
RC4                       153525    25.4437
RC4 Only                  140       0.0232
RC4 Preferred             12783     2.1185
RC4 forced in TLS1.1+     6911      1.1454
x:FF 29 3DES Only         597       0.0989
x:FF 29 3DES Preferred    2030      0.3364
x:FF 29 RC4 Only          193       0.032
x:FF 29 RC4 Preferred     14404     2.3872
x:FF 29 incompatible      530       0.0878
x:FF 35 3DES Only         605       0.1003
x:FF 35 3DES Preferred    1956      0.3242
x:FF 35 RC4 Only          218       0.0361
x:FF 35 RC4 Preferred     14418     2.3895
x:FF 35 incompatible      532       0.0882
x:FF 44 3DES Only         3874      0.642
x:FF 44 3DES Preferred    7464      1.237
x:FF 44 incompatible      750       0.1243
y:DHE-RSA-SEED-SHA        79084     13.1066
y:IDEA-CBC-SHA            75906     12.5799
y:SEED-SHA                90103     14.9328
z:ADH-AES128-GCM-SHA256   428       0.0709
z:ADH-AES128-SHA          715       0.1185
z:ADH-AES128-SHA256       281       0.0466
z:ADH-AES256-GCM-SHA384   442       0.0733
z:ADH-AES256-SHA          759       0.1258
z:ADH-AES256-SHA256       284       0.0471
z:ADH-CAMELLIA128-SHA     368       0.061
z:ADH-CAMELLIA128-SHA256  1         0.0002
z:ADH-CAMELLIA256-SHA     393       0.0651
z:ADH-CAMELLIA256-SHA256  1         0.0002
z:ADH-DES-CBC-SHA         279       0.0462
z:ADH-DES-CBC3-SHA        720       0.1193
z:ADH-RC4-MD5             517       0.0857
z:ADH-SEED-SHA            298       0.0494
z:AECDH-AES128-SHA        9498      1.5741
z:AECDH-AES256-SHA        9566      1.5854
z:AECDH-DES-CBC3-SHA      9463      1.5683
z:AECDH-NULL-SHA          60        0.0099
z:AECDH-RC4-SHA           8940      1.4816
z:DES-CBC-MD5             6015      0.9969
z:DES-CBC-SHA             33753     5.5939
z:DES-CBC3-MD5            15538     2.5751
z:ECDHE-RSA-NULL-SHA      67        0.0111
z:EDH-RSA-DES-CBC-SHA     28904     4.7903
z:EXP-ADH-DES-CBC-SHA     180       0.0298
z:EXP-ADH-RC4-MD5         178       0.0295
z:EXP-DES-CBC-SHA         9916      1.6434
z:EXP-EDH-RSA-DES-CBC-SHA 7950      1.3176
z:EXP-RC2-CBC-MD5         11811     1.9574
z:EXP-RC4-MD5             12355     2.0476
z:EXP1024-DES-CBC-SHA     3045      0.5046
z:EXP1024-RC4-SHA         3108      0.5151
z:IDEA-CBC-MD5            1225      0.203
z:NULL-MD5                196       0.0325
z:NULL-SHA                201       0.0333
z:NULL-SHA256             39        0.0065
z:RC2-CBC-MD5             6171      1.0227
z:RC4-64-MD5              692       0.1147

Cipher ordering           Count     Percent
-------------------------+---------+-------
Client side               149228    24.7316
Server side               454163    75.2684

Supported Handshakes      Count     Percent
-------------------------+---------+-------
ADH                       918       0.1521
AECDH                     9574      1.5867
DHE                       327644    54.3004
ECDH                      2         0.0003
ECDHE                     532966    88.3285
ECDHE and DHE             285103    47.2501
RSA                       517470    85.7603

Supported PFS             Count     Percent  PFS Percent
-------------------------+---------+--------+-----------
DH,1024bits               115821    19.195   35.3496
DH,2048bits               196265    32.527   59.9019
DH,2049bits               1         0.0002   0.0003
DH,2236bits               77        0.0128   0.0235
DH,2432bits               3         0.0005   0.0009
DH,3072bits               141       0.0234   0.043
DH,3092bits               2         0.0003   0.0006
DH,3196bits               1         0.0002   0.0003
DH,4096bits               14972     2.4813   4.5696
DH,512bits                122       0.0202   0.0372
DH,6144bits               1         0.0002   0.0003
DH,768bits                355       0.0588   0.1083
DH,8192bits               7         0.0012   0.0021
ECDH,B-571,570bits        4696      0.7783   0.8811
ECDH,K-163,163bits        1         0.0002   0.0002
ECDH,P-192,192bits        68        0.0113   0.0128
ECDH,P-224,224bits        91        0.0151   0.0171
ECDH,P-256,256bits        500295    82.9139  93.87
ECDH,P-384,384bits        12707     2.1059   2.3842
ECDH,P-521,521bits        17146     2.8416   3.2171
ECDH,brainpoolP512r1,512bits 3         0.0005   0.0006
ECDH,secp256k1,256bits    1         0.0002   0.0002
Prefer DH,1024bits        42440     7.0336   12.9531
Prefer DH,2048bits        4955      0.8212   1.5123
Prefer DH,3072bits        9         0.0015   0.0027
Prefer DH,3092bits        2         0.0003   0.0006
Prefer DH,4096bits        379       0.0628   0.1157
Prefer DH,768bits         33        0.0055   0.0101
Prefer ECDH,B-571,570bits 4438      0.7355   0.8327
Prefer ECDH,K-163,163bits 1         0.0002   0.0002
Prefer ECDH,P-192,192bits 1         0.0002   0.0002
Prefer ECDH,P-224,224bits 89        0.0147   0.0167
Prefer ECDH,P-256,256bits 465038    77.0708  87.2547
Prefer ECDH,P-384,384bits 10660     1.7667   2.0001
Prefer ECDH,P-521,521bits 15901     2.6353   2.9835
Prefer ECDH,brainpoolP512r1,512bits 3         0.0005   0.0006
Prefer ECDH,secp256k1,256bits 1         0.0002   0.0002
Prefer PFS                543950    90.1488  0
Support PFS               575507    95.3788  0

Supported ECC curves      Count     Percent 
-------------------------+---------+--------
None                      2         0.0003   
None Only                 2         0.0003   
brainpoolP256r1           27492     4.5562   
brainpoolP384r1           27491     4.5561   
brainpoolP512r1           27484     4.5549   
prime192v1                1647      0.273    
prime256v1                510415    84.5911  
prime256v1 Only           428464    71.0093  
secp160k1                 1528      0.2532   
secp160r1                 1536      0.2546   
secp160r2                 1528      0.2532   
secp192k1                 1543      0.2557   
secp224k1                 1625      0.2693   
secp224r1                 5406      0.8959   
secp256k1                 29683     4.9194   
secp384r1                 88419     14.6537  
secp384r1 Only            5169      0.8567   
secp521r1                 58499     9.695    
secp521r1 Only            153       0.0254   
sect163k1                 1531      0.2537   
sect163k1 Only            3         0.0005   
sect163r1                 1529      0.2534   
sect163r2                 1529      0.2534   
sect193r1                 1529      0.2534   
sect193r2                 1529      0.2534   
sect233k1                 1614      0.2675   
sect233r1                 1614      0.2675   
sect239k1                 1614      0.2675   
sect283k1                 28930     4.7946   
sect283k1 Only            2         0.0003   
sect283r1                 28927     4.7941   
sect409k1                 28927     4.7941   
sect409r1                 28927     4.7941   
sect571k1                 28927     4.7941   
sect571r1                 28930     4.7946   
server                    38445     6.3715   
server Only               38445     6.3715   

Unsupported curve fallback     Count     Percent 
------------------------------+---------+--------
False                          532806    88.3019  
unknown                        70585     11.6981  

ECC curve ordering        Count     Percent 
-------------------------+---------+--------
                          36744     6.0896   
client                    18027     2.9876   
server                    478197    79.2516  
unknown                   70423     11.6712  

TLSv1.2 PFS supported sigalgs  Count     Percent 
------------------------------+---------+--------
ECDSA-SHA1                     54563     9.0427   
ECDSA-SHA1 Only                9         0.0015   
ECDSA-SHA224                   54587     9.0467   
ECDSA-SHA256                   72567     12.0265  
ECDSA-SHA384                   72639     12.0385  
ECDSA-SHA512                   72750     12.0569  
ECDSA-SHA512 Only              118       0.0196   
RSA-MD5                        23842     3.9513   
RSA-SHA1                       462908    76.7178  
RSA-SHA1 Only                  30278     5.018    
RSA-SHA224                     387875    64.2825  
RSA-SHA256                     441866    73.2305  
RSA-SHA256 Only                8016      1.3285   
RSA-SHA384                     403401    66.8557  
RSA-SHA384 Only                4         0.0007   
RSA-SHA512                     403342    66.8459  
RSA-SHA512 Only                131       0.0217   

TLSv1.2 PFS ordering           Count     Percent 
------------------------------+---------+--------
client                         282677    46.8481  
indeterminate                  38        0.0063   
intolerant                     6561      1.0874   
order-fallback                 4         0.0007   
server                         236059    39.1221  
unsupported                    14339     2.3764   

TLSv1.2 PFS sigalg fallback    Count     Percent 
------------------------------+---------+--------
ECDSA SHA1                     54456     9.025    
ECDSA intolerant               652       0.1081   
ECDSA pfs-rsa-SHA512           17783     2.9472   
ECDSA soft-nopfs               15        0.0025   
RSA False                      23629     3.916    
RSA SHA1                       399316    66.1786  
RSA intolerant                 50007     8.2877   
RSA pfs-ecdsa-SHA512           99        0.0164   
RSA soft-nopfs                 389       0.0645   

Renegotiation             Count     Percent 
-------------------------+---------+--------
False                     4550      0.7541   
insecure                  15701     2.6021   
secure                    583140    96.6438  

Compression               Count     Percent 
-------------------------+---------+--------
1 (zlib compression)      6683      1.1076   
False                     4550      0.7541   
NONE                      592158    98.1384  

TLS session ticket hint   Count     Percent 
-------------------------+---------+--------
1                         3         0.0005   
1 only                    3         0.0005   
5                         8         0.0013   
5 only                    8         0.0013   
10                        9         0.0015   
10 only                   9         0.0015   
15                        7         0.0012   
15 only                   7         0.0012   
30                        29        0.0048   
30 only                   29        0.0048   
60                        172       0.0285   
60 only                   166       0.0275   
65                        2         0.0003   
65 only                   2         0.0003   
70                        6         0.001    
70 only                   4         0.0007   
75                        1         0.0002   
75 only                   1         0.0002   
90                        1         0.0002   
90 only                   1         0.0002   
100                       15        0.0025   
100 only                  15        0.0025   
120                       28        0.0046   
120 only                  28        0.0046   
128                       3         0.0005   
128 only                  2         0.0003   
150                       2         0.0003   
180                       83        0.0138   
180 only                  80        0.0133   
240                       12        0.002    
240 only                  12        0.002    
300                       306995    50.8783  
300 only                  304055    50.391   
302                       2         0.0003   
302 only                  2         0.0003   
360                       3         0.0005   
360 only                  2         0.0003   
400                       8         0.0013   
400 only                  8         0.0013   
420                       120       0.0199   
420 only                  103       0.0171   
480                       11        0.0018   
480 only                  11        0.0018   
500                       4         0.0007   
500 only                  4         0.0007   
540                       4         0.0007   
540 only                  4         0.0007   
600                       29961     4.9654   
600 only                  29817     4.9416   
630                       1         0.0002   
630 only                  1         0.0002   
700                       1         0.0002   
700 only                  1         0.0002   
720                       6         0.001    
720 only                  6         0.001    
840                       2         0.0003   
840 only                  2         0.0003   
900                       1560      0.2585   
900 only                  1541      0.2554   
960                       3         0.0005   
960 only                  3         0.0005   
1000                      1         0.0002   
1000 only                 1         0.0002   
1200                      3528      0.5847   
1200 only                 3525      0.5842   
1210                      2         0.0003   
1210 only                 2         0.0003   
1320                      1         0.0002   
1320 only                 1         0.0002   
1380                      1         0.0002   
1380 only                 1         0.0002   
1440                      1         0.0002   
1440 only                 1         0.0002   
1500                      4         0.0007   
1500 only                 3         0.0005   
1800                      860       0.1425   
1800 only                 839       0.139    
1980                      2         0.0003   
1980 only                 2         0.0003   
2100                      1         0.0002   
2400                      8         0.0013   
2400 only                 8         0.0013   
2700                      12        0.002    
2700 only                 12        0.002    
3000                      41        0.0068   
3000 only                 41        0.0068   
3600                      1100      0.1823   
3600 only                 1090      0.1806   
3900                      2         0.0003   
3900 only                 2         0.0003   
4200                      2         0.0003   
4200 only                 1         0.0002   
4500                      1         0.0002   
4500 only                 1         0.0002   
5160                      1         0.0002   
5160 only                 1         0.0002   
5400                      15        0.0025   
5400 only                 9         0.0015   
6000                      341       0.0565   
6000 only                 340       0.0563   
7200                      15389     2.5504   
7200 only                 15355     2.5448   
7500                      2         0.0003   
7500 only                 2         0.0003   
9000                      2         0.0003   
9000 only                 2         0.0003   
10800                     5322      0.882    
10800 only                5300      0.8784   
14400                     147       0.0244   
14400 only                144       0.0239   
18000                     9         0.0015   
18000 only                8         0.0013   
21600                     4353      0.7214   
21600 only                4353      0.7214   
25200                     1         0.0002   
25200 only                1         0.0002   
28800                     2164      0.3586   
28800 only                2164      0.3586   
30000                     2         0.0003   
30000 only                1         0.0002   
36000                     1239      0.2053   
36000 only                1231      0.204    
43200                     67        0.0111   
43200 only                67        0.0111   
54000                     2         0.0003   
54000 only                2         0.0003   
60000                     3         0.0005   
60000 only                3         0.0005   
64800                     73037     12.1044  
64800 only                73018     12.1013  
72000                     12        0.002    
72000 only                12        0.002    
79200                     1         0.0002   
79200 only                1         0.0002   
86400                     3232      0.5356   
86400 only                3222      0.534    
100800                    9169      1.5196   
100800 only               9156      1.5174   
108000                    1         0.0002   
108000 only               1         0.0002   
115200                    1         0.0002   
115200 only               1         0.0002   
129600                    6         0.001    
129600 only               6         0.001    
172800                    49        0.0081   
172800 only               49        0.0081   
216000                    3         0.0005   
216000 only               3         0.0005   
259200                    3         0.0005   
259200 only               3         0.0005   
432000                    1         0.0002   
432000 only               1         0.0002   
604800                    1         0.0002   
864000                    2         0.0003   
864000 only               2         0.0003   
7776000                   2         0.0003   
7776000 only              2         0.0003   
None                      147458    24.4382  
None only                 144200    23.8983  

Certificate sig alg     Count     Percent 
-------------------------+---------+--------
None                      10178     1.6868   
ecdsa-with-SHA256         70598     11.7002  
sha1WithRSAEncryption     17351     2.8756   
sha256WithRSAEncryption   533303    88.3843  
sha384WithRSAEncryption   7         0.0012   
sha512WithRSAEncryption   77        0.0128   

Certificate key size    Count     Percent 
-------------------------+---------+--------
ECDSA 256                 72865     12.0759  
ECDSA 384                 41        0.0068   
ECDSA 521                 1         0.0002   
RSA 1024                  14        0.0023   
RSA 2048                  516458    85.5926  
RSA 2049                  4         0.0007   
RSA 2056                  1         0.0002   
RSA 2058                  3         0.0005   
RSA 2059                  1         0.0002   
RSA 2080                  6         0.001    
RSA 2084                  1         0.0002   
RSA 2086                  1         0.0002   
RSA 2096                  3         0.0005   
RSA 2408                  1         0.0002   
RSA 2432                  6         0.001    
RSA 2560                  1         0.0002   
RSA 2948                  1         0.0002   
RSA 3072                  158       0.0262   
RSA 3096                  2         0.0003   
RSA 3120                  1         0.0002   
RSA 3248                  3         0.0005   
RSA 4048                  3         0.0005   
RSA 4056                  21        0.0035   
RSA 4069                  1         0.0002   
RSA 4086                  3         0.0005   
RSA 4092                  2         0.0003   
RSA 4094                  1         0.0002   
RSA 4095                  1         0.0002   
RSA 4096                  33887     5.6161   
RSA 4196                  1         0.0002   
RSA 8192                  12        0.002    
RSA 8392                  1         0.0002   
RSA/ECDSA Dual Stack      20097     3.3307

OCSP stapling             Count     Percent 
-------------------------+---------+--------
Supported                 139486    23.117   
Unsupported               463905    76.883   

Supported Protocols       Count     Percent
-------------------------+---------+-------
SSL2                      15694     2.601
SSL2 Only                 9         0.0015
SSL3                      88647     14.6915
SSL3 Only                 325       0.0539
SSL3 or TLS1 Only         47120     7.8092
SSL3 or lower Only        335       0.0555
TLS1                      590402    97.8473
TLS1 Only                 28435     4.7125
TLS1 or lower Only        61759     10.2353
TLS1.1                    532582    88.2648
TLS1.1 Only               43        0.0071
TLS1.1 or up Only         12475     2.0675
TLS1.2                    539663    89.4384
TLS1.2 Only               3587      0.5945
TLS1.2, 1.0 but not 1.1   5029      0.8335

Client Hello intolerance                 Count     Percent
----------------------------------------+---------+-------
Huge Cipher List                         539862    89.4713
Huge Cipher List (trunc 16388)           143271    23.7443
SSL 3.254                                19882     3.295
TLS 1.0                                  66391     11.003
TLS 1.1                                  3190      0.5287
TLS 1.2                                  67        0.0111
TLS 1.3                                  7896      1.3086
TLS 1.4                                  14758     2.4458
Xmas tree                                43001     7.1266
x:missing information                    44        0.0073



Statistics from 544239 chains provided by 734331 hosts

Server provided chains    Count     Percent
-------------------------+---------+-------
complete                  493648    67.2242
incomplete                20056     2.7312
untrusted                 220627    30.0446

Trusted chain statistics
========================

Chain length              Count     Percent
-------------------------+---------+-------
2                         1         0.0002
3                         540295    99.2753
4                         3930      0.7221
5                         13        0.0024

CA key size in chains     Count
-------------------------+---------
ECDSA 256                 30197     
ECDSA 384                 30193     
RSA 1024                  9         
RSA 2045                  2         
RSA 2048                  845143    
RSA 4096                  186889    

Chains with CA key        Count     Percent
-------------------------+---------+-------
ECDSA 256                 30197     5.5485
ECDSA 384                 30193     5.5477
RSA 1024                  7         0.0013
RSA 2045                  2         0.0004
RSA 2048                  513612    94.3725
RSA 4096                  186227    34.2179

Signature algorithm (ex. root) Count
------------------------------+---------
ecdsa-with-SHA384              30185     
sha1WithRSAEncryption          20474     
sha256WithRSAEncryption        330105    
sha384WithRSAEncryption        167373    
sha512WithRSAEncryption        57        

Eff. host cert chain LoS  Count     Percent
-------------------------+---------+-------
80                        20448     3.7572
112                       493575    90.6909
128                       30216     5.552

Most popular root CAs                         Count     Percent
---------------------------------------------+---------+-------
(d6325660) COMODO RSA Certification Authority 149876    27.5386
(2c543cd1) GeoTrust Global CA                 82272     15.1169
(cbf06781) Go Daddy Root Certificate Authorit 46152     8.4801
(5ad8a5d6) GlobalSign Root CA                 42046     7.7256
(b204d74a) VeriSign Class 3 Public Primary Ce 30585     5.6198
(eed8c118) COMODO ECC Certification Authority 30178     5.545
(244b5494) DigiCert High Assurance EV Root CA 21202     3.8957
(2e4eed3c) thawte Primary Root CA             17390     3.1953
(fc5a8f99) USERTrust RSA Certification Author 17354     3.1887
(2e5ac55d) DST Root CA X3                     16492     3.0303
(653b494a) Baltimore CyberTrust Root          11315     2.079
(3513523f) DigiCert Global Root CA            10347     1.9012
(ae8153b9) StartCom Certification Authority   9044      1.6618
(4bfab552) Starfield Root Certificate Authori 9012      1.6559
(e2799e36) GeoTrust Primary Certification Aut 6148      1.1297
(480720ec) GeoTrust Primary Certification Aut 5775      1.0611
(02265526) Entrust Root Certification Authori 3969      0.7293
(ba89ed3b) thawte Primary Root CA - G3        3394      0.6236
(8096d0a9) Certification Authority of WoSign  2877      0.5286
(157753a5) AddTrust External CA Root          2782      0.5112

Most popular intermediate CA                  Count     Percent
---------------------------------------------+---------+-------
(8d28ae65) COMODO RSA Domain Validation Secur 100923    18.5439
(27eb7704) Go Daddy Secure Certificate Author 46152     8.4801
(53f3e569) RapidSSL SHA256 CA - G3            40339     7.412
(6cfa716c) COMODO ECC Domain Validation Secur 30126     5.5354
(7d9c641e) Symantec Class 3 Secure Server CA  21662     3.9802
(1400f578) cPanel, Inc. Certification Authori 19580     3.5977
(38ae8eda) DigiCert SHA2 High Assurance Serve 17140     3.1494
(4f06f81d) Let's Encrypt Authority X3         16492     3.0303
(16744f0c) AlphaSSL CA - SHA256 - G2          16239     2.9838
(493a2f06) COMODO RSA Domain Validation Secur 13442     2.4699
(10310d4b) GeoTrust SSL CA - G3               13423     2.4664
(80ecc636) RapidSSL SHA256 CA                 12795     2.351
(d7d634d4) GlobalSign Domain Validation CA -  11432     2.1005
(b85455c4) GlobalSign Organization Validation 11363     2.0879
(c43a77d9) COMODO RSA Organization Validation 11217     2.061
(85cf5865) DigiCert SHA2 Secure Server CA     10208     1.8756
(9ad474ec) thawte SSL CA - G2                 9146      1.6805
(cd7781e5) Starfield Secure Certificate Autho 9012      1.6559
(d84ef247) GeoTrust DV SSL CA - G4            7163      1.3161
(a0f7ac3e) Symantec Class 3 EV SSL CA - G3    7144      1.3127
(3d97f5e2) Verizon Akamai SureServer CA G14-S 7025      1.2908
(fd917e82) SecureCore RSA DV CA               6995      1.2853
(b71a5f76) GeoTrust EV SSL CA - G4            5724      1.0517
(661c52cc) thawte DV SSL CA - G2              5368      0.9863
(e22cd3f0) COMODO RSA Extended Validation Sec 4365      0.802
(7f8496de) StartCom Class 1 DV Server CA      3678      0.6758
(45bfefc3) DigiCert SHA2 Extended Validation  3527      0.6481
(2835d715) Entrust Certification Authority -  3328      0.6115
(f131b364) RapidSSL CA                        3180      0.5843
(98d7cad7) GeoTrust DV SSL CA - G3            3154      0.5795



Scan performed between 20th of July and 17th of August 2016

June 2016 scan results

Sorry, no analysis this month.

SSL/TLS survey of 593851 websites from Alexa's top 1 million
Stats only from connections that did provide valid certificates
(or anonymous DH from servers that do also have valid certificate installed)


Supported Ciphers         Count     Percent
-------------------------+---------+-------
3DES                      525961    88.5678
3DES Only                 605       0.1019
3DES Preferred            1797      0.3026
3DES forced in TLS1.1+    978       0.1647
AES                       589255    99.2261
AES Only                  43606     7.3429
AES-CBC                   588687    99.1304
AES-CBC Only              5565      0.9371
AES-GCM                   490658    82.6231
AES-GCM Only              520       0.0876
CAMELLIA                  261701    44.0685
CAMELLIA Only             2         0.0003
CHACHA20                  81256     13.6829
Insecure                  56141     9.4537
RC4                       166167    27.9813
RC4 Only                  158       0.0266
RC4 Preferred             13843     2.3311
RC4 forced in TLS1.1+     7176      1.2084
x:FF 29 3DES Only         654       0.1101
x:FF 29 3DES Preferred    2164      0.3644
x:FF 29 RC4 Only          233       0.0392
x:FF 29 RC4 Preferred     16139     2.7177
x:FF 29 incompatible      518       0.0872
x:FF 35 3DES Only         662       0.1115
x:FF 35 3DES Preferred    2094      0.3526
x:FF 35 RC4 Only          273       0.046
x:FF 35 RC4 Preferred     16162     2.7216
x:FF 35 incompatible      522       0.0879
x:FF 44 3DES Only         4368      0.7355
x:FF 44 3DES Preferred    8162      1.3744
x:FF 44 incompatible      795       0.1339
y:DHE-RSA-SEED-SHA        79533     13.3928
y:IDEA-CBC-SHA            76113     12.8169
y:SEED-SHA                90128     15.1769
z:ADH-AES128-GCM-SHA256   430       0.0724
z:ADH-AES128-SHA          771       0.1298
z:ADH-AES128-SHA256       268       0.0451
z:ADH-AES256-GCM-SHA384   444       0.0748
z:ADH-AES256-SHA          809       0.1362
z:ADH-AES256-SHA256       269       0.0453
z:ADH-CAMELLIA128-SHA     401       0.0675
z:ADH-CAMELLIA128-SHA256  1         0.0002
z:ADH-CAMELLIA256-SHA     424       0.0714
z:ADH-CAMELLIA256-SHA256  1         0.0002
z:ADH-DES-CBC-SHA         326       0.0549
z:ADH-DES-CBC3-SHA        781       0.1315
z:ADH-RC4-MD5             571       0.0962
z:ADH-SEED-SHA            322       0.0542
z:AECDH-AES128-SHA        10202     1.7179
z:AECDH-AES256-SHA        10261     1.7279
z:AECDH-DES-CBC3-SHA      10168     1.7122
z:AECDH-NULL-SHA          94        0.0158
z:AECDH-RC4-SHA           9605      1.6174
z:DES-CBC-MD5             6658      1.1212
z:DES-CBC-SHA             35044     5.9011
z:DES-CBC3-MD5            17074     2.8751
z:ECDHE-RSA-NULL-SHA      100       0.0168
z:EDH-RSA-DES-CBC-SHA     29995     5.0509
z:EXP-ADH-DES-CBC-SHA     181       0.0305
z:EXP-ADH-RC4-MD5         180       0.0303
z:EXP-DES-CBC-SHA         10901     1.8356
z:EXP-EDH-RSA-DES-CBC-SHA 8667      1.4595
z:EXP-RC2-CBC-MD5         13108     2.2073
z:EXP-RC4-MD5             13716     2.3097
z:EXP1024-DES-CBC-SHA     3463      0.5831
z:EXP1024-RC4-SHA         3524      0.5934
z:IDEA-CBC-MD5            1453      0.2447
z:NULL-MD5                233       0.0392
z:NULL-SHA                238       0.0401
z:NULL-SHA256             36        0.0061
z:RC2-CBC-MD5             6966      1.173
z:RC4-64-MD5              757       0.1275

Cipher ordering           Count     Percent
-------------------------+---------+-------
Client side               152565    25.6908
Server side               441286    74.3092

Supported Handshakes      Count     Percent
-------------------------+---------+-------
ADH                       979       0.1649
AECDH                     10271     1.7296
DHE                       320930    54.0422
ECDH                      2         0.0003
ECDHE                     517887    87.2082
ECDHE and DHE             274945    46.2987
RSA                       509769    85.8412

Supported PFS             Count     Percent  PFS Percent
-------------------------+---------+--------+-----------
DH,1024bits               119481    20.1197  37.2296
DH,1028bits               1         0.0002   0.0003
DH,2048bits               188192    31.6901  58.6396
DH,2236bits               78        0.0131   0.0243
DH,2430bits               1         0.0002   0.0003
DH,2432bits               3         0.0005   0.0009
DH,2560bits               1         0.0002   0.0003
DH,3072bits               132       0.0222   0.0411
DH,3092bits               2         0.0003   0.0006
DH,3196bits               1         0.0002   0.0003
DH,4046bits               1         0.0002   0.0003
DH,4094bits               1         0.0002   0.0003
DH,4096bits               12637     2.128    3.9376
DH,512bits                108       0.0182   0.0337
DH,6144bits               1         0.0002   0.0003
DH,768bits                385       0.0648   0.12
DH,8192bits               8         0.0013   0.0025
ECDH,B-571,570bits        3072      0.5173   0.5932
ECDH,K-163,163bits        1         0.0002   0.0002
ECDH,P-192,192bits        60        0.0101   0.0116
ECDH,P-224,224bits        94        0.0158   0.0182
ECDH,P-256,256bits        490672    82.6254  94.745
ECDH,P-384,384bits        9474      1.5953   1.8294
ECDH,P-521,521bits        16461     2.7719   3.1785
ECDH,brainpoolP512r1,512bits 1         0.0002   0.0002
ECDH,secp256k1,256bits    1         0.0002   0.0002
Prefer DH,1024bits        45380     7.6416   14.1402
Prefer DH,2048bits        5635      0.9489   1.7558
Prefer DH,3072bits        8         0.0013   0.0025
Prefer DH,3092bits        2         0.0003   0.0006
Prefer DH,4096bits        398       0.067    0.124
Prefer DH,768bits         44        0.0074   0.0137
Prefer ECDH,B-571,570bits 2840      0.4782   0.5484
Prefer ECDH,K-163,163bits 1         0.0002   0.0002
Prefer ECDH,P-192,192bits 1         0.0002   0.0002
Prefer ECDH,P-224,224bits 92        0.0155   0.0178
Prefer ECDH,P-256,256bits 453139    76.3052  87.4977
Prefer ECDH,P-384,384bits 7350      1.2377   1.4192
Prefer ECDH,P-521,521bits 15215     2.5621   2.9379
Prefer ECDH,brainpoolP512r1,512bits 1         0.0002   0.0002
Prefer ECDH,secp256k1,256bits 1         0.0002   0.0002
Prefer PFS                530107    89.266   0
Support PFS               563872    94.9518  0

Supported ECC curves      Count     Percent 
-------------------------+---------+--------
brainpoolP256r1           17814     2.9997   
brainpoolP384r1           17827     3.0019   
brainpoolP512r1           17836     3.0034   
prime192v1                1799      0.3029   
prime256v1                513258    86.4288  
prime256v1 Only           427959    72.065   
secp160k1                 1678      0.2826   
secp160r1                 1688      0.2842   
secp160r2                 1678      0.2826   
secp192k1                 1693      0.2851   
secp224k1                 1780      0.2997   
secp224r1                 5748      0.9679   
secp256k1                 20085     3.3822   
secp384r1                 88954     14.9792  
secp384r1 Only            3672      0.6183   
secp521r1                 50953     8.5801   
secp521r1 Only            140       0.0236   
sect163k1                 1684      0.2836   
sect163k1 Only            2         0.0003   
sect163r1                 1682      0.2832   
sect163r2                 1681      0.2831   
sect193r1                 1681      0.2831   
sect193r2                 1681      0.2831   
sect233k1                 1770      0.2981   
sect233r1                 1768      0.2977   
sect239k1                 1768      0.2977   
sect283k1                 19394     3.2658   
sect283r1                 19392     3.2655   
sect409k1                 19395     3.266    
sect409r1                 19391     3.2653   
sect571k1                 19395     3.266    
sect571r1                 19395     3.266    

Unsupported curve fallback     Count     Percent 
------------------------------+---------+--------
False                          56371     9.4924   
True                           391090    65.8566  
order-specific                 45        0.0076   
unknown                        146345    24.6434  

ECC curve ordering        Count     Percent 
-------------------------+---------+--------
client                    13249     2.231    
inconclusive-noecc        8         0.0013   
server                    503853    84.845   
unknown                   76741     12.9226  

TLSv1.2 PFS supported sigalgs  Count     Percent 
------------------------------+---------+--------
ECDSA-SHA1                     53286     8.973    
ECDSA-SHA1 Only                8         0.0013   
ECDSA-SHA224                   53248     8.9666   
ECDSA-SHA256                   71063     11.9665  
ECDSA-SHA384                   71064     11.9666  
ECDSA-SHA512                   71074     11.9683  
ECDSA-SHA512 Only              16        0.0027   
RSA-MD5                        27142     4.5705   
RSA-SHA1                       447072    75.2835  
RSA-SHA1 Only                  34046     5.7331   
RSA-SHA224                     371135    62.4963  
RSA-SHA256                     422358    71.1219  
RSA-SHA256 Only                8044      1.3545   
RSA-SHA384                     383992    64.6613  
RSA-SHA384 Only                4         0.0007   
RSA-SHA512                     384022    64.6664  
RSA-SHA512 Only                209       0.0352   

TLSv1.2 PFS ordering           Count     Percent 
------------------------------+---------+--------
client                         280809    47.2861  
indeterminate                  54        0.0091   
intolerant                     6465      1.0887   
order-fallback                 8         0.0013   
server                         220388    37.1117  
unsupported                    15018     2.5289   

TLSv1.2 PFS sigalg fallback    Count     Percent 
------------------------------+---------+--------
ECDSA SHA1                     53230     8.9635   
ECDSA intolerant               189       0.0318   
ECDSA pfs-rsa-SHA512           17719     2.9837   
ECDSA soft-nopfs               7         0.0012   
RSA False                      26845     4.5205   
RSA SHA1                       386610    65.1022  
RSA intolerant                 43313     7.2936   
RSA pfs-ecdsa-SHA512           27        0.0045   
RSA soft-nopfs                 474       0.0798   

Renegotiation             Count     Percent 
-------------------------+---------+--------
False                     4962      0.8356   
insecure                  16550     2.7869   
secure                    572339    96.3775  

Compression               Count     Percent 
-------------------------+---------+--------
1 (zlib compression)      7077      1.1917   
False                     4962      0.8356   
NONE                      581812    97.9727  

TLS session ticket hint   Count     Percent 
-------------------------+---------+--------
1                         2         0.0003   
1 only                    2         0.0003   
2                         1         0.0002   
2 only                    1         0.0002   
5                         5         0.0008   
5 only                    5         0.0008   
10                        8         0.0013   
10 only                   8         0.0013   
15                        8         0.0013   
15 only                   8         0.0013   
30                        25        0.0042   
30 only                   25        0.0042   
60                        166       0.028    
60 only                   161       0.0271   
65                        2         0.0003   
65 only                   2         0.0003   
70                        8         0.0013   
70 only                   8         0.0013   
75                        1         0.0002   
75 only                   1         0.0002   
90                        1         0.0002   
90 only                   1         0.0002   
100                       16        0.0027   
100 only                  16        0.0027   
120                       27        0.0045   
120 only                  27        0.0045   
128                       6         0.001    
128 only                  6         0.001    
150                       2         0.0003   
180                       78        0.0131   
180 only                  74        0.0125   
240                       14        0.0024   
240 only                  14        0.0024   
244                       2         0.0003   
244 only                  2         0.0003   
300                       298609    50.2835  
300 only                  295255    49.7187  
302                       2         0.0003   
302 only                  2         0.0003   
360                       3         0.0005   
360 only                  2         0.0003   
400                       6         0.001    
400 only                  6         0.001    
420                       129       0.0217   
420 only                  111       0.0187   
450                       1         0.0002   
450 only                  1         0.0002   
480                       11        0.0019   
480 only                  11        0.0019   
500                       3         0.0005   
500 only                  3         0.0005   
540                       4         0.0007   
540 only                  4         0.0007   
600                       28678     4.8292   
600 only                  28547     4.8071   
660                       1         0.0002   
660 only                  1         0.0002   
700                       1         0.0002   
700 only                  1         0.0002   
720                       3         0.0005   
720 only                  3         0.0005   
840                       2         0.0003   
840 only                  2         0.0003   
900                       1532      0.258    
900 only                  1515      0.2551   
960                       3         0.0005   
960 only                  3         0.0005   
1000                      1         0.0002   
1000 only                 1         0.0002   
1200                      3512      0.5914   
1200 only                 3508      0.5907   
1210                      2         0.0003   
1210 only                 2         0.0003   
1320                      1         0.0002   
1320 only                 1         0.0002   
1380                      1         0.0002   
1380 only                 1         0.0002   
1440                      1         0.0002   
1440 only                 1         0.0002   
1500                      6         0.001    
1500 only                 5         0.0008   
1800                      751       0.1265   
1800 only                 734       0.1236   
1980                      2         0.0003   
1980 only                 2         0.0003   
2100                      2         0.0003   
2100 only                 1         0.0002   
2400                      10        0.0017   
2400 only                 10        0.0017   
2700                      11        0.0019   
2700 only                 11        0.0019   
3000                      42        0.0071   
3000 only                 42        0.0071   
3300                      1         0.0002   
3300 only                 1         0.0002   
3600                      1079      0.1817   
3600 only                 1070      0.1802   
3900                      1         0.0002   
3900 only                 1         0.0002   
4200                      1         0.0002   
4500                      1         0.0002   
4500 only                 1         0.0002   
5160                      1         0.0002   
5160 only                 1         0.0002   
5400                      19        0.0032   
5400 only                 6         0.001    
6000                      352       0.0593   
6000 only                 352       0.0593   
7200                      15154     2.5518   
7200 only                 15130     2.5478   
9000                      2         0.0003   
9000 only                 2         0.0003   
10800                     5334      0.8982   
10800 only                5324      0.8965   
14400                     116       0.0195   
14400 only                116       0.0195   
18000                     9         0.0015   
18000 only                9         0.0015   
21600                     4287      0.7219   
21600 only                4286      0.7217   
25200                     1         0.0002   
25200 only                1         0.0002   
28800                     2555      0.4302   
28800 only                2555      0.4302   
30000                     3         0.0005   
30000 only                1         0.0002   
36000                     1220      0.2054   
36000 only                1209      0.2036   
43200                     65        0.0109   
43200 only                65        0.0109   
54000                     1         0.0002   
54000 only                1         0.0002   
54647                     1         0.0002   
54660                     1         0.0002   
54674                     1         0.0002   
54690                     1         0.0002   
54703                     1         0.0002   
54722                     1         0.0002   
54737                     1         0.0002   
54751                     1         0.0002   
60000                     2         0.0003   
60000 only                2         0.0003   
64800                     70759     11.9153  
64800 only                70736     11.9114  
72000                     12        0.002    
72000 only                12        0.002    
79200                     1         0.0002   
79200 only                1         0.0002   
86400                     2990      0.5035   
86400 only                2984      0.5025   
100800                    9026      1.5199   
100800 only               9015      1.5181   
108000                    1         0.0002   
108000 only               1         0.0002   
115200                    1         0.0002   
115200 only               1         0.0002   
129600                    6         0.001    
129600 only               6         0.001    
172800                    47        0.0079   
172800 only               47        0.0079   
216000                    4         0.0007   
216000 only               3         0.0005   
259200                    2         0.0003   
259200 only               2         0.0003   
432000                    1         0.0002   
432000 only               1         0.0002   
604800                    1         0.0002   
604800 only               1         0.0002   
864000                    2         0.0003   
864000 only               2         0.0003   
7776000                   1         0.0002   
7776000 only              1         0.0002   
None                      150742    25.3838  
None only                 147105    24.7714  

Certificate sig alg     Count     Percent 
-------------------------+---------+--------
None                      10920     1.8388   
ecdsa-with-SHA256         68463     11.5286  
sha1WithRSAEncryption     21372     3.5989   
sha256WithRSAEncryption   521742    87.8574  
sha384WithRSAEncryption   8         0.0013   
sha512WithRSAEncryption   69        0.0116   

Certificate key size    Count     Percent 
-------------------------+---------+--------
ECDSA 256                 71108     11.974   
ECDSA 384                 38        0.0064   
ECDSA 521                 1         0.0002   
RSA 1024                  15        0.0025   
RSA 2048                  511834    86.189   
RSA 2049                  3         0.0005   
RSA 2056                  1         0.0002   
RSA 2058                  3         0.0005   
RSA 2059                  1         0.0002   
RSA 2080                  6         0.001    
RSA 2084                  2         0.0003   
RSA 2086                  1         0.0002   
RSA 2096                  3         0.0005   
RSA 2408                  1         0.0002   
RSA 2432                  3         0.0005   
RSA 2560                  1         0.0002   
RSA 2948                  1         0.0002   
RSA 3072                  163       0.0274   
RSA 3073                  1         0.0002   
RSA 3096                  2         0.0003   
RSA 3248                  3         0.0005   
RSA 4048                  4         0.0007   
RSA 4056                  18        0.003    
RSA 4069                  1         0.0002   
RSA 4086                  4         0.0007   
RSA 4092                  2         0.0003   
RSA 4094                  1         0.0002   
RSA 4095                  1         0.0002   
RSA 4096                  30991     5.2186   
RSA 4196                  1         0.0002   
RSA 8192                  10        0.0017   
RSA 8392                  1         0.0002   
RSA/ECDSA Dual Stack      20358     3.4281

OCSP stapling             Count     Percent 
-------------------------+---------+--------
Supported                 126688    21.3333  
Unsupported               467163    78.6667  

Supported Protocols       Count     Percent
-------------------------+---------+-------
SSL2                      17236     2.9024
SSL2 Only                 12        0.002
SSL3                      99629     16.7768
SSL3 Only                 497       0.0837
SSL3 or TLS1 Only         52946     8.9157
SSL3 or lower Only        505       0.085
TLS1                      582034    98.0101
TLS1 Only                 32797     5.5228
TLS1 or lower Only        68913     11.6044
TLS1.1                    515189    86.7539
TLS1.1 Only               42        0.0071
TLS1.1 or up Only         11134     1.8749
TLS1.2                    522729    88.0236
TLS1.2 Only               3290      0.554
TLS1.2, 1.0 but not 1.1   5865      0.9876





Statistics from 628845 chains provided by 728648 hosts

Server provided chains    Count     Percent
-------------------------+---------+-------
complete                  570337    78.2733
incomplete                21286     2.9213
untrusted                 137025    18.8054

Trusted chain statistics
========================

Chain length              Count     Percent
-------------------------+---------+-------
2                         1         0.0002
3                         625155    99.4132
4                         3676      0.5846
5                         13        0.0021

CA key size in chains     Count
-------------------------+---------
ECDSA 256                 68458     
ECDSA 384                 68457     
RSA 1024                  8         
RSA 2045                  2         
RSA 2048                  927971    
RSA 4096                  196495    

Chains with CA key        Count     Percent
-------------------------+---------+-------
ECDSA 256                 68458     10.8863
ECDSA 384                 68456     10.886
RSA 1024                  6         0.001
RSA 2045                  2         0.0003
RSA 2048                  559959    89.0456
RSA 4096                  195838    31.1425

Signature algorithm (ex. root) Count
------------------------------+---------
ecdsa-with-SHA384              68447     
sha1WithRSAEncryption          24541     
sha256WithRSAEncryption        363378    
sha384WithRSAEncryption        176120    
sha512WithRSAEncryption        60        

Eff. host cert chain LoS  Count     Percent
-------------------------+---------+-------
80                        24524     3.8998
112                       535845    85.211
128                       68476     10.8892

Most popular root CAs                         Count     Percent
---------------------------------------------+---------+-------
(d6325660) COMODO RSA Certification Authority 158376    25.1852
(2c543cd1) GeoTrust Global CA                 95542     15.1933
(eed8c118) COMODO ECC Certification Authority 68438     10.8831
(cbf06781) Go Daddy Root Certificate Authorit 49514     7.8738
(5ad8a5d6) GlobalSign Root CA                 48382     7.6938
(b204d74a) VeriSign Class 3 Public Primary Ce 32086     5.1024
(2e5ac55d) DST Root CA X3                     26043     4.1414
(244b5494) DigiCert High Assurance EV Root CA 20408     3.2453
(2e4eed3c) thawte Primary Root CA             19033     3.0267
(fc5a8f99) USERTrust RSA Certification Author 17598     2.7985
(653b494a) Baltimore CyberTrust Root          11671     1.8559
(3513523f) DigiCert Global Root CA            10585     1.6832
(ae8153b9) StartCom Certification Authority   9453      1.5032
(4bfab552) Starfield Root Certificate Authori 8502      1.352


Scan performed between 19th of June and 6th of July 2016

May 2016 scan results

No detailed analysis, sorry.

SSL/TLS survey of 588324 websites from Alexa's top 1 million
Stats only from connections that did provide valid certificates
(or anonymous DH from servers that do also have valid certificate installed)


Supported Ciphers         Count     Percent
-------------------------+---------+-------
3DES                      521557    88.6513
3DES Only                 618       0.105
3DES Preferred            1789      0.3041
3DES forced in TLS1.1+    964       0.1639
AES                       583623    99.201
AES Only                  42928     7.2967
AES-CBC                   583065    99.1061
AES-CBC Only              6504      1.1055
AES-GCM                   482505    82.0135
AES-GCM Only              514       0.0874
CAMELLIA                  258710    43.9741
CAMELLIA Only             3         0.0005
CHACHA20                  80738     13.7234
CHACHA20 Only             4         0.0007
Insecure                  56788     9.6525
RC4                       168525    28.6449
RC4 Only                  166       0.0282
RC4 Preferred             14971     2.5447
RC4 forced in TLS1.1+     8083      1.3739
x:FF 29 3DES Only         661       0.1124
x:FF 29 3DES Preferred    2145      0.3646
x:FF 29 RC4 Only          245       0.0416
x:FF 29 RC4 Preferred     16797     2.8551
x:FF 29 incompatible      506       0.086
x:FF 35 3DES Only         669       0.1137
x:FF 35 3DES Preferred    2073      0.3524
x:FF 35 RC4 Only          285       0.0484
x:FF 35 RC4 Preferred     16818     2.8586
x:FF 35 incompatible      510       0.0867
x:FF 44 3DES Only         4449      0.7562
x:FF 44 3DES Preferred    8286      1.4084
x:FF 44 incompatible      795       0.1351
y:DHE-RSA-SEED-SHA        79291     13.4774
y:IDEA-CBC-SHA            75311     12.8009
y:SEED-SHA                89316     15.1814
z:ADH-AES128-GCM-SHA256   414       0.0704
z:ADH-AES128-SHA          763       0.1297
z:ADH-AES128-SHA256       275       0.0467
z:ADH-AES256-GCM-SHA384   425       0.0722
z:ADH-AES256-SHA          792       0.1346
z:ADH-AES256-SHA256       275       0.0467
z:ADH-CAMELLIA128-SHA     406       0.069
z:ADH-CAMELLIA128-SHA256  1         0.0002
z:ADH-CAMELLIA256-SHA     423       0.0719
z:ADH-CAMELLIA256-SHA256  1         0.0002
z:ADH-DES-CBC-SHA         338       0.0575
z:ADH-DES-CBC3-SHA        773       0.1314
z:ADH-RC4-MD5             578       0.0982
z:ADH-SEED-SHA            332       0.0564
z:AECDH-AES128-SHA        10505     1.7856
z:AECDH-AES256-SHA        10564     1.7956
z:AECDH-DES-CBC3-SHA      10475     1.7805
z:AECDH-NULL-SHA          91        0.0155
z:AECDH-RC4-SHA           9925      1.687
z:DES-CBC-MD5             6864      1.1667
z:DES-CBC-SHA             35454     6.0263
z:DES-CBC3-MD5            17200     2.9236
z:ECDHE-RSA-NULL-SHA      98        0.0167
z:EDH-RSA-DES-CBC-SHA     30414     5.1696
z:EXP-ADH-DES-CBC-SHA     188       0.032
z:EXP-ADH-RC4-MD5         186       0.0316
z:EXP-DES-CBC-SHA         11293     1.9195
z:EXP-EDH-RSA-DES-CBC-SHA 8983      1.5269
z:EXP-RC2-CBC-MD5         13517     2.2975
z:EXP-RC4-MD5             14150     2.4051
z:EXP1024-DES-CBC-SHA     3580      0.6085
z:EXP1024-RC4-SHA         3641      0.6189
z:IDEA-CBC-MD5            1486      0.2526
z:NULL-MD5                239       0.0406
z:NULL-SHA                242       0.0411
z:NULL-SHA256             33        0.0056
z:RC2-CBC-MD5             7118      1.2099
z:RC4-64-MD5              762       0.1295

Cipher ordering           Count     Percent
-------------------------+---------+-------
Client side               151229    25.7051
Server side               437095    74.2949

Supported Handshakes      Count     Percent
-------------------------+---------+-------
ADH                       941       0.1599
AECDH                     10576     1.7976
DHE                       319231    54.2611
ECDH                      2         0.0003
ECDHE                     509684    86.6332
ECDHE and DHE             272378    46.2973
RSA                       505946    85.9979

Supported PFS             Count     Percent  PFS Percent
-------------------------+---------+--------+-----------
DH,1024bits               122627    20.8434  38.4132
DH,2048bits               183782    31.2382  57.5702
DH,2236bits               92        0.0156   0.0288
DH,2430bits               1         0.0002   0.0003
DH,2432bits               3         0.0005   0.0009
DH,2560bits               1         0.0002   0.0003
DH,3072bits               122       0.0207   0.0382
DH,3092bits               2         0.0003   0.0006
DH,3196bits               1         0.0002   0.0003
DH,4094bits               1         0.0002   0.0003
DH,4096bits               12216     2.0764   3.8267
DH,512bits                91        0.0155   0.0285
DH,6144bits               1         0.0002   0.0003
DH,768bits                384       0.0653   0.1203
DH,8192bits               9         0.0015   0.0028
ECDH,B-571,570bits        2788      0.4739   0.547
ECDH,K-163,163bits        1         0.0002   0.0002
ECDH,P-192,192bits        39        0.0066   0.0077
ECDH,P-224,224bits        92        0.0156   0.0181
ECDH,P-256,256bits        484945    82.4282  95.1462
ECDH,P-384,384bits        8059      1.3698   1.5812
ECDH,P-521,521bits        15676     2.6645   3.0756
ECDH,brainpoolP512r1,512bits 1         0.0002   0.0002
Prefer DH,1024bits        46364     7.8807   14.5237
Prefer DH,2048bits        5558      0.9447   1.7411
Prefer DH,3072bits        11        0.0019   0.0034
Prefer DH,4096bits        389       0.0661   0.1219
Prefer DH,768bits         45        0.0076   0.0141
Prefer ECDH,B-571,570bits 2562      0.4355   0.5027
Prefer ECDH,K-163,163bits 1         0.0002   0.0002
Prefer ECDH,P-192,192bits 1         0.0002   0.0002
Prefer ECDH,P-224,224bits 89        0.0151   0.0175
Prefer ECDH,P-256,256bits 446551    75.9022  87.6133
Prefer ECDH,P-384,384bits 6159      1.0469   1.2084
Prefer ECDH,P-521,521bits 14444     2.4551   2.8339
Prefer ECDH,brainpoolP512r1,512bits 1         0.0002   0.0002
Prefer PFS                522175    88.7564  0
Support PFS               556537    94.597   0

Supported ECC curves      Count     Percent 
-------------------------+---------+--------
brainpoolP256r1           15666     2.6628   
brainpoolP384r1           15673     2.664    
brainpoolP512r1           15677     2.6647   
prime192v1                1721      0.2925   
prime256v1                505771    85.9681  
prime256v1 Only           424806    72.2061  
secp160k1                 1634      0.2777   
secp160r1                 1641      0.2789   
secp160r2                 1633      0.2776   
secp192k1                 1647      0.2799   
secp224k1                 1732      0.2944   
secp224r1                 5585      0.9493   
secp256k1                 17871     3.0376   
secp384r1                 83624     14.2139  
secp384r1 Only            2663      0.4526   
secp521r1                 47374     8.0524   
secp521r1 Only            142       0.0241   
sect163k1                 1637      0.2782   
sect163r1                 1636      0.2781   
sect163r2                 1637      0.2782   
sect193r1                 1636      0.2781   
sect193r2                 1636      0.2781   
sect233k1                 1728      0.2937   
sect233r1                 1725      0.2932   
sect239k1                 1721      0.2925   
sect283k1                 17205     2.9244   
sect283r1                 17203     2.9241   
sect409k1                 17203     2.9241   
sect409r1                 17200     2.9236   
sect571k1                 17204     2.9242   
sect571r1                 17205     2.9244   

Unsupported curve fallback     Count     Percent 
------------------------------+---------+--------
False                          56188     9.5505   
True                           384116    65.2899  
order-specific                 30        0.0051   
unknown                        147990    25.1545  

ECC curve ordering        Count     Percent 
-------------------------+---------+--------
client                    12072     2.0519   
inconclusive-noecc        8         0.0014   
server                    496534    84.3981  
unknown                   79710     13.5487  

TLSv1.2 PFS supported sigalgs  Count     Percent 
------------------------------+---------+--------
ECDSA-SHA1                     53235     9.0486   
ECDSA-SHA1 Only                7         0.0012   
ECDSA-SHA224                   53208     9.044    
ECDSA-SHA256                   70734     12.023   
ECDSA-SHA384                   70725     12.0214  
ECDSA-SHA512                   70735     12.0231  
ECDSA-SHA512 Only              16        0.0027   
RSA-MD5                        32419     5.5104   
RSA-SHA1                       439804    74.7554  
RSA-SHA1 Only                  34182     5.8101   
RSA-SHA224                     364514    61.958   
RSA-SHA256                     414576    70.4673  
RSA-SHA256 Only                7888      1.3408   
RSA-SHA384                     377143    64.1046  
RSA-SHA384 Only                4         0.0007   
RSA-SHA512                     377071    64.0924  
RSA-SHA512 Only                85        0.0144   

TLSv1.2 PFS ordering           Count     Percent 
------------------------------+---------+--------
client                         276407    46.9821  
indeterminate                  52        0.0088   
intolerant                     6076      1.0328   
order-fallback                 9         0.0015   
server                         217108    36.9028  
unsupported                    15976     2.7155   

TLSv1.2 PFS sigalg fallback    Count     Percent 
------------------------------+---------+--------
ECDSA SHA1                     53190     9.0409   
ECDSA intolerant               134       0.0228   
ECDSA pfs-rsa-SHA512           17450     2.9661   
ECDSA soft-nopfs               9         0.0015   
RSA False                      32115     5.4587   
RSA SHA1                       374923    63.7273  
RSA intolerant                 41684     7.0852   
RSA pfs-ecdsa-SHA512           26        0.0044   
RSA soft-nopfs                 481       0.0818   

Renegotiation             Count     Percent 
-------------------------+---------+--------
False                     5021      0.8534   
insecure                  16740     2.8454   
secure                    566563    96.3012  

Compression               Count     Percent 
-------------------------+---------+--------
1 (zlib compression)      7345      1.2485   
False                     5021      0.8534   
NONE                      575958    97.8981  

TLS session ticket hint   Count     Percent 
-------------------------+---------+--------
1                         2         0.0003   
1 only                    2         0.0003   
2                         1         0.0002   
2 only                    1         0.0002   
5                         9         0.0015   
5 only                    9         0.0015   
10                        8         0.0014   
10 only                   8         0.0014   
15                        7         0.0012   
15 only                   7         0.0012   
30                        24        0.0041   
30 only                   24        0.0041   
60                        159       0.027    
60 only                   151       0.0257   
65                        2         0.0003   
65 only                   2         0.0003   
70                        8         0.0014   
70 only                   7         0.0012   
75                        1         0.0002   
75 only                   1         0.0002   
90                        1         0.0002   
90 only                   1         0.0002   
100                       15        0.0025   
100 only                  15        0.0025   
120                       24        0.0041   
120 only                  24        0.0041   
128                       6         0.001    
128 only                  5         0.0008   
150                       2         0.0003   
180                       72        0.0122   
180 only                  70        0.0119   
240                       13        0.0022   
240 only                  13        0.0022   
244                       2         0.0003   
244 only                  2         0.0003   
300                       294538    50.0639  
300 only                  291166    49.4908  
302                       2         0.0003   
302 only                  2         0.0003   
360                       3         0.0005   
360 only                  2         0.0003   
400                       4         0.0007   
400 only                  4         0.0007   
420                       133       0.0226   
420 only                  113       0.0192   
480                       11        0.0019   
480 only                  10        0.0017   
500                       3         0.0005   
500 only                  3         0.0005   
540                       4         0.0007   
540 only                  4         0.0007   
600                       28048     4.7674   
600 only                  27923     4.7462   
700                       3         0.0005   
700 only                  3         0.0005   
840                       2         0.0003   
840 only                  2         0.0003   
900                       1508      0.2563   
900 only                  1487      0.2528   
960                       4         0.0007   
960 only                  4         0.0007   
1000                      1         0.0002   
1000 only                 1         0.0002   
1200                      3403      0.5784   
1200 only                 3400      0.5779   
1210                      2         0.0003   
1210 only                 2         0.0003   
1320                      1         0.0002   
1320 only                 1         0.0002   
1380                      1         0.0002   
1380 only                 1         0.0002   
1440                      1         0.0002   
1440 only                 1         0.0002   
1500                      7         0.0012   
1500 only                 6         0.001    
1800                      698       0.1186   
1800 only                 680       0.1156   
1980                      2         0.0003   
1980 only                 2         0.0003   
2100                      2         0.0003   
2100 only                 1         0.0002   
2160                      1         0.0002   
2160 only                 1         0.0002   
2400                      9         0.0015   
2400 only                 9         0.0015   
2700                      10        0.0017   
2700 only                 10        0.0017   
3000                      38        0.0065   
3000 only                 38        0.0065   
3300                      1         0.0002   
3300 only                 1         0.0002   
3600                      1035      0.1759   
3600 only                 1024      0.1741   
3900                      2         0.0003   
3900 only                 2         0.0003   
4200                      1         0.0002   
4500                      1         0.0002   
4500 only                 1         0.0002   
5160                      1         0.0002   
5160 only                 1         0.0002   
5400                      22        0.0037   
5400 only                 6         0.001    
6000                      345       0.0586   
6000 only                 345       0.0586   
7200                      15012     2.5517   
7200 only                 14995     2.5488   
8100                      1         0.0002   
8100 only                 1         0.0002   
9000                      2         0.0003   
9000 only                 2         0.0003   
10800                     5061      0.8602   
10800 only                5045      0.8575   
14400                     106       0.018    
14400 only                106       0.018    
18000                     11        0.0019   
18000 only                11        0.0019   
21600                     4326      0.7353   
21600 only                4324      0.735    
25200                     1         0.0002   
25200 only                1         0.0002   
28800                     2688      0.4569   
28800 only                2688      0.4569   
30000                     3         0.0005   
30000 only                1         0.0002   
36000                     1246      0.2118   
36000 only                1240      0.2108   
43200                     61        0.0104   
43200 only                61        0.0104   
54000                     1         0.0002   
54000 only                1         0.0002   
60000                     2         0.0003   
60000 only                2         0.0003   
64800                     70216     11.9349  
64800 only                70188     11.9302  
72000                     12        0.002    
72000 only                12        0.002    
79200                     1         0.0002   
79200 only                1         0.0002   
86400                     2835      0.4819   
86400 only                2826      0.4803   
100800                    9392      1.5964   
100800 only               9375      1.5935   
108000                    1         0.0002   
108000 only               1         0.0002   
115200                    1         0.0002   
115200 only               1         0.0002   
129600                    7         0.0012   
129600 only               7         0.0012   
172800                    55        0.0093   
172800 only               55        0.0093   
216000                    4         0.0007   
216000 only               4         0.0007   
259200                    3         0.0005   
259200 only               3         0.0005   
432000                    1         0.0002   
432000 only               1         0.0002   
604800                    1         0.0002   
864000                    3         0.0005   
864000 only               3         0.0005   
7776000                   1         0.0002   
7776000 only              1         0.0002   
None                      150759    25.6252  
None only                 147078    24.9995  

Certificate sig alg     Count     Percent 
-------------------------+---------+--------
None                      11191     1.9022   
ecdsa-with-SHA256         67977     11.5543  
sha1WithRSAEncryption     23775     4.0411   
sha256WithRSAEncryption   514022    87.3706  
sha384WithRSAEncryption   8         0.0014   
sha512WithRSAEncryption   67        0.0114   

Certificate key size    Count     Percent 
-------------------------+---------+--------
ECDSA 256                 70749     12.0255  
ECDSA 384                 34        0.0058   
ECDSA 521                 1         0.0002   
RSA 1024                  17        0.0029   
RSA 2048                  507589    86.2771  
RSA 2049                  2         0.0003   
RSA 2056                  1         0.0002   
RSA 2058                  3         0.0005   
RSA 2059                  1         0.0002   
RSA 2084                  1         0.0002   
RSA 2086                  1         0.0002   
RSA 2096                  3         0.0005   
RSA 2408                  1         0.0002   
RSA 2432                  2         0.0003   
RSA 2560                  1         0.0002   
RSA 2948                  1         0.0002   
RSA 3072                  156       0.0265   
RSA 3073                  1         0.0002   
RSA 3096                  2         0.0003   
RSA 3248                  2         0.0003   
RSA 4048                  4         0.0007   
RSA 4056                  16        0.0027   
RSA 4069                  1         0.0002   
RSA 4086                  3         0.0005   
RSA 4092                  2         0.0003   
RSA 4094                  1         0.0002   
RSA 4095                  1         0.0002   
RSA 4096                  29945     5.0899   
RSA 4196                  1         0.0002   
RSA 8192                  11        0.0019   
RSA 8392                  1         0.0002   
RSA/ECDSA Dual Stack      20215     3.436

OCSP stapling             Count     Percent 
-------------------------+---------+--------
Supported                 127611    21.6906  
Unsupported               460713    78.3094  

Supported Protocols       Count     Percent
-------------------------+---------+-------
SSL2                      17372     2.9528
SSL2 Only                 13        0.0022
SSL3                      102349    17.3967
SSL3 Only                 1020      0.1734
SSL3 or TLS1 Only         54445     9.2543
SSL3 or lower Only        1028      0.1747
TLS1                      576797    98.0407
TLS1 Only                 33030     5.6143
TLS1 or lower Only        70001     11.8984
TLS1.1                    507108    86.1954
TLS1.1 Only               42        0.0071
TLS1.1 or up Only         10330     1.7558
TLS1.2                    515617    87.6417
TLS1.2 Only               3098      0.5266
TLS1.2, 1.0 but not 1.1   7000      1.1898



Statistics from 622291 chains provided by 724741 hosts

Server provided chains    Count     Percent
-------------------------+---------+-------
complete                  563959    77.8152
incomplete                21088     2.9097
untrusted                 139694    19.275

Trusted chain statistics
========================

Chain length              Count     Percent
-------------------------+---------+-------
2                         2         0.0003
3                         618971    99.4665
4                         3305      0.5311
5                         13        0.0021

CA key size in chains     Count
-------------------------+---------
ECDSA 256                 67969     
ECDSA 384                 67967     
RSA 1024                  10        
RSA 2045                  2         
RSA 2048                  918447    
RSA 4096                  193516    

Chains with CA key        Count     Percent
-------------------------+---------+-------
ECDSA 256                 67969     10.9224
ECDSA 384                 67967     10.9221
RSA 1024                  8         0.0013
RSA 2045                  2         0.0003
RSA 2048                  553908    89.0111
RSA 4096                  192863    30.9924

Signature algorithm (ex. root) Count
------------------------------+---------
ecdsa-with-SHA384              67958     
sha1WithRSAEncryption          27126     
sha256WithRSAEncryption        356410    
sha384WithRSAEncryption        174062    
sha512WithRSAEncryption        64        

Eff. host cert chain LoS  Count     Percent
-------------------------+---------+-------
80                        27123     4.3586
112                       527185    84.7168
128                       67983     10.9246

Most common root CAs                          Count     Percent
---------------------------------------------+---------+-------
(d6325660) COMODO RSA Certification Authority 156327    25.1212
(2c543cd1) GeoTrust Global CA                 97389     15.6501
(eed8c118) COMODO ECC Certification Authority 67950     10.9193
(5ad8a5d6) GlobalSign Root CA                 54936     8.828
(cbf06781) Go Daddy Root Certificate Authorit 48751     7.8341
(b204d74a) VeriSign Class 3 Public Primary Ce 32016     5.1449
(244b5494) DigiCert High Assurance EV Root CA 19865     3.1922
(2e4eed3c) thawte Primary Root CA             18906     3.0381
(fc5a8f99) USERTrust RSA Certification Author 17597     2.8278
(2e5ac55d) DST Root CA X3                     17594     2.8273
(653b494a) Baltimore CyberTrust Root          11729     1.8848
(3513523f) DigiCert Global Root CA            10305     1.656
(ae8153b9) StartCom Certification Authority   9737      1.5647
(4bfab552) Starfield Root Certificate Authori 8211      1.3195


Scan performed between 30th of May and 18th of June 2016

April 2016 scan results

Again, no analysis, just raw statistics, sorry.

SSL/TLS survey of 554044 websites from Alexa's top 1 million
Stats only from connections that did provide valid certificates
(or anonymous DH from servers that do also have valid certificate installed)


Supported Ciphers         Count     Percent
-------------------------+---------+-------
3DES                      488020    88.0833
3DES Only                 590       0.1065
3DES Preferred            1772      0.3198
3DES forced in TLS1.1+    936       0.1689
AES                       549187    99.1234
AES Only                  42441     7.6602
AES-CBC                   548762    99.0466
AES-CBC Only              8334      1.5042
AES-GCM                   448629    80.9735
AES-GCM Only              378       0.0682
CAMELLIA                  241430    43.576
CAMELLIA Only             1         0.0002
CHACHA20                  75592     13.6437
Insecure                  54139     9.7716
RC4                       160923    29.0452
RC4 Only                  183       0.033
RC4 Preferred             15628     2.8207
RC4 forced in TLS1.1+     8360      1.5089
x:FF 29 3DES Only         639       0.1153
x:FF 29 3DES Preferred    2130      0.3844
x:FF 29 RC4 Only          254       0.0458
x:FF 29 RC4 Preferred     17323     3.1266
x:FF 29 incompatible      272       0.0491
x:FF 35 3DES Only         645       0.1164
x:FF 35 3DES Preferred    2044      0.3689
x:FF 35 RC4 Only          301       0.0543
x:FF 35 RC4 Preferred     17346     3.1308
x:FF 35 incompatible      276       0.0498
x:FF 44 3DES Only         4576      0.8259
x:FF 44 3DES Preferred    8336      1.5046
x:FF 44 incompatible      577       0.1041
y:DHE-RSA-SEED-SHA        71951     12.9865
y:IDEA-CBC-SHA            67468     12.1774
y:SEED-SHA                82250     14.8454
z:ADH-AES128-GCM-SHA256   401       0.0724
z:ADH-AES128-SHA          730       0.1318
z:ADH-AES128-SHA256       275       0.0496
z:ADH-AES256-GCM-SHA384   411       0.0742
z:ADH-AES256-SHA          748       0.135
z:ADH-AES256-SHA256       274       0.0495
z:ADH-CAMELLIA128-SHA     390       0.0704
z:ADH-CAMELLIA256-SHA     400       0.0722
z:ADH-DES-CBC-SHA         321       0.0579
z:ADH-DES-CBC3-SHA        738       0.1332
z:ADH-RC4-MD5             539       0.0973
z:ADH-SEED-SHA            312       0.0563
z:AECDH-AES128-SHA        9716      1.7537
z:AECDH-AES256-SHA        9763      1.7621
z:AECDH-DES-CBC3-SHA      9685      1.7481
z:AECDH-NULL-SHA          85        0.0153
z:AECDH-RC4-SHA           9132      1.6482
z:DES-CBC-MD5             7224      1.3039
z:DES-CBC-SHA             33578     6.0605
z:DES-CBC3-MD5            17444     3.1485
z:ECDHE-RSA-NULL-SHA      95        0.0171
z:EDH-RSA-DES-CBC-SHA     28962     5.2274
z:EXP-ADH-DES-CBC-SHA     173       0.0312
z:EXP-ADH-RC4-MD5         171       0.0309
z:EXP-DES-CBC-SHA         11121     2.0072
z:EXP-EDH-RSA-DES-CBC-SHA 8776      1.584
z:EXP-RC2-CBC-MD5         13375     2.4141
z:EXP-RC4-MD5             14006     2.528
z:EXP1024-DES-CBC-SHA     3639      0.6568
z:EXP1024-RC4-SHA         3688      0.6657
z:IDEA-CBC-MD5            1523      0.2749
z:NULL-MD5                214       0.0386
z:NULL-SHA                218       0.0393
z:NULL-SHA256             32        0.0058
z:RC2-CBC-MD5             7396      1.3349
z:RC4-64-MD5              767       0.1384

Cipher ordering           Count     Percent
-------------------------+---------+-------
Client side               134999    24.3661
Server side               419045    75.6339

Supported Handshakes      Count     Percent
-------------------------+---------+-------
ADH                       885       0.1597
AECDH                     9773      1.7639
DHE                       298929    53.954
ECDH                      2         0.0004
ECDHE                     476485    86.0013
ECDHE and DHE             253657    45.7828
RSA                       475653    85.8511

Supported PFS             Count     Percent  PFS Percent
-------------------------+---------+--------+-----------
DH,1024bits               116515    21.0299  38.9775
DH,1536bits               1         0.0002   0.0003
DH,2048bits               170990    30.8622  57.2009
DH,2236bits               69        0.0125   0.0231
DH,2432bits               3         0.0005   0.001
DH,2560bits               1         0.0002   0.0003
DH,3072bits               111       0.02     0.0371
DH,3092bits               1         0.0002   0.0003
DH,4094bits               1         0.0002   0.0003
DH,4096bits               10885     1.9646   3.6413
DH,4098bits               1         0.0002   0.0003
DH,512bits                64        0.0116   0.0214
DH,6144bits               1         0.0002   0.0003
DH,768bits                377       0.068    0.1261
DH,8192bits               9         0.0016   0.003
ECDH,B-571,570bits        2314      0.4177   0.4856
ECDH,K-163,163bits        1         0.0002   0.0002
ECDH,P-192,192bits        23        0.0042   0.0048
ECDH,P-224,224bits        84        0.0152   0.0176
ECDH,P-256,256bits        456709    82.4319  95.8496
ECDH,P-384,384bits        5908      1.0663   1.2399
ECDH,P-521,521bits        13327     2.4054   2.7969
Prefer DH,1024bits        43925     7.9281   14.6941
Prefer DH,1536bits        1         0.0002   0.0003
Prefer DH,2048bits        5768      1.0411   1.9296
Prefer DH,3072bits        6         0.0011   0.002
Prefer DH,4096bits        423       0.0763   0.1415
Prefer DH,768bits         54        0.0097   0.0181
Prefer ECDH,B-571,570bits 2090      0.3772   0.4386
Prefer ECDH,K-163,163bits 1         0.0002   0.0002
Prefer ECDH,P-224,224bits 81        0.0146   0.017
Prefer ECDH,P-256,256bits 419866    75.7821  88.1174
Prefer ECDH,P-384,384bits 4218      0.7613   0.8852
Prefer ECDH,P-521,521bits 12182     2.1987   2.5566
Prefer PFS                488615    88.1906  0
Support PFS               521757    94.1725  0

Supported ECC curves      Count     Percent 
-------------------------+---------+--------
brainpoolP256r1           7632      1.3775   
brainpoolP384r1           7634      1.3779   
brainpoolP512r1           7637      1.3784   
prime192v1                1557      0.281    
prime256v1                473202    85.4087  
prime256v1 Only           404241    72.9619  
secp160k1                 1490      0.2689   
secp160r1                 1497      0.2702   
secp160r2                 1488      0.2686   
secp192k1                 1502      0.2711   
secp224k1                 1576      0.2845   
secp224r1                 4971      0.8972   
secp256k1                 10618     1.9165   
secp384r1                 70010     12.6362  
secp384r1 Only            1082      0.1953   
secp521r1                 36615     6.6087   
secp521r1 Only            140       0.0253   
sect163k1                 1492      0.2693   
sect163k1 Only            1         0.0002   
sect163r1                 1490      0.2689   
sect163r2                 1490      0.2689   
sect193r1                 1490      0.2689   
sect193r2                 1489      0.2688   
sect233k1                 1566      0.2826   
sect233r1                 1566      0.2826   
sect239k1                 1565      0.2825   
sect283k1                 9047      1.6329   
sect283k1 Only            1         0.0002   
sect283r1                 9044      1.6324   
sect409k1                 9041      1.6318   
sect409r1                 9038      1.6313   
sect571k1                 9044      1.6324   
sect571r1                 9045      1.6325   

Unsupported curve fallback     Count     Percent 
------------------------------+---------+--------
False                          46285     8.354    
True                           365389    65.9495  
order-specific                 61        0.011    
unknown                        142309    25.6855  

ECC curve ordering        Count     Percent 
-------------------------+---------+--------
client                    9132      1.6482   
inconclusive-noecc        4         0.0007   
server                    465324    83.9868  
unknown                   79584     14.3642  

TLSv1.2 PFS supported sigalgs  Count     Percent 
------------------------------+---------+--------
ECDSA-SHA1                     50518     9.118    
ECDSA-SHA1 Only                3         0.0005   
ECDSA-SHA224                   50534     9.1209   
ECDSA-SHA256                   66231     11.9541  
ECDSA-SHA384                   66277     11.9624  
ECDSA-SHA512                   66334     11.9727  
ECDSA-SHA512 Only              61        0.011    
RSA-MD5                        41528     7.4954   
RSA-SHA1                       408670    73.7613  
RSA-SHA1 Only                  36069     6.5101   
RSA-SHA224                     340011    61.369   
RSA-SHA256                     380914    68.7516  
RSA-SHA256 Only                7319      1.321    
RSA-SHA384                     345799    62.4136  
RSA-SHA384 Only                4         0.0007   
RSA-SHA512                     345776    62.4095  
RSA-SHA512 Only                118       0.0213   

TLSv1.2 PFS ordering           Count     Percent 
------------------------------+---------+--------
client                         255972    46.2007  
indeterminate                  42        0.0076   
intolerant                     5716      1.0317   
order-fallback                 9         0.0016   
server                         203222    36.6798  
unsupported                    17516     3.1615   

TLSv1.2 PFS sigalg fallback    Count     Percent 
------------------------------+---------+--------
ECDSA SHA1                     50464     9.1083   
ECDSA intolerant               381       0.0688   
ECDSA pfs-rsa-SHA512           15610     2.8175   
ECDSA soft-nopfs               2         0.0004   
RSA False                      41178     7.4323   
RSA SHA1                       336118    60.6663  
RSA intolerant                 40148     7.2464   
RSA pfs-ecdsa-SHA512           45        0.0081   
RSA soft-nopfs                 512       0.0924   

Renegotiation             Count     Percent 
-------------------------+---------+--------
False                     5199      0.9384   
insecure                  15950     2.8788   
secure                    532895    96.1828  

Compression               Count     Percent 
-------------------------+---------+--------
1 (zlib compression)      7539      1.3607   
False                     5199      0.9384   
NONE                      541306    97.7009  

TLS session ticket hint   Count     Percent 
-------------------------+---------+--------
1                         4         0.0007   
1 only                    4         0.0007   
2                         2         0.0004   
2 only                    2         0.0004   
5                         8         0.0014   
5 only                    8         0.0014   
10                        8         0.0014   
10 only                   8         0.0014   
15                        6         0.0011   
15 only                   6         0.0011   
30                        19        0.0034   
30 only                   18        0.0032   
60                        167       0.0301   
60 only                   164       0.0296   
65                        2         0.0004   
65 only                   2         0.0004   
70                        6         0.0011   
70 only                   4         0.0007   
75                        1         0.0002   
75 only                   1         0.0002   
100                       16        0.0029   
100 only                  16        0.0029   
120                       28        0.0051   
120 only                  28        0.0051   
128                       3         0.0005   
128 only                  3         0.0005   
150                       2         0.0004   
180                       66        0.0119   
180 only                  64        0.0116   
240                       11        0.002    
240 only                  11        0.002    
244                       2         0.0004   
244 only                  2         0.0004   
300                       272999    49.2739  
300 only                  269600    48.6604  
302                       3         0.0005   
302 only                  3         0.0005   
360                       3         0.0005   
360 only                  2         0.0004   
400                       5         0.0009   
400 only                  5         0.0009   
420                       122       0.022    
420 only                  105       0.019    
480                       10        0.0018   
480 only                  10        0.0018   
500                       4         0.0007   
500 only                  4         0.0007   
540                       3         0.0005   
540 only                  3         0.0005   
600                       28373     5.1211   
600 only                  28233     5.0958   
660                       1         0.0002   
660 only                  1         0.0002   
700                       3         0.0005   
700 only                  3         0.0005   
840                       2         0.0004   
840 only                  2         0.0004   
900                       1388      0.2505   
900 only                  1366      0.2466   
960                       2         0.0004   
960 only                  2         0.0004   
1000                      1         0.0002   
1000 only                 1         0.0002   
1200                      2912      0.5256   
1200 only                 2907      0.5247   
1210                      2         0.0004   
1210 only                 2         0.0004   
1320                      1         0.0002   
1320 only                 1         0.0002   
1380                      1         0.0002   
1380 only                 1         0.0002   
1440                      1         0.0002   
1440 only                 1         0.0002   
1500                      6         0.0011   
1500 only                 5         0.0009   
1800                      579       0.1045   
1800 only                 568       0.1025   
1980                      2         0.0004   
1980 only                 2         0.0004   
2100                      2         0.0004   
2100 only                 1         0.0002   
2160                      1         0.0002   
2160 only                 1         0.0002   
2400                      8         0.0014   
2400 only                 8         0.0014   
2700                      9         0.0016   
2700 only                 9         0.0016   
3000                      25        0.0045   
3000 only                 25        0.0045   
3300                      1         0.0002   
3300 only                 1         0.0002   
3600                      865       0.1561   
3600 only                 850       0.1534   
3900                      1         0.0002   
3900 only                 1         0.0002   
4200                      1         0.0002   
5160                      1         0.0002   
5160 only                 1         0.0002   
5400                      15        0.0027   
5400 only                 9         0.0016   
5940                      1         0.0002   
5940 only                 1         0.0002   
6000                      297       0.0536   
6000 only                 297       0.0536   
7200                      15195     2.7426   
7200 only                 15175     2.739    
7500                      1         0.0002   
7500 only                 1         0.0002   
10800                     4136      0.7465   
10800 only                4122      0.744    
14400                     95        0.0171   
14400 only                95        0.0171   
18000                     10        0.0018   
18000 only                10        0.0018   
21600                     4179      0.7543   
21600 only                4179      0.7543   
25200                     1         0.0002   
25200 only                1         0.0002   
28800                     3321      0.5994   
28800 only                3321      0.5994   
30000                     1         0.0002   
30000 only                1         0.0002   
36000                     1080      0.1949   
36000 only                1071      0.1933   
38854                     1         0.0002   
38866                     1         0.0002   
38879                     1         0.0002   
38893                     1         0.0002   
38908                     1         0.0002   
38925                     1         0.0002   
38940                     1         0.0002   
38953                     1         0.0002   
43200                     55        0.0099   
43200 only                55        0.0099   
60000                     2         0.0004   
60000 only                2         0.0004   
64800                     65043     11.7397  
64800 only                65041     11.7393  
72000                     9         0.0016   
72000 only                9         0.0016   
79200                     1         0.0002   
79200 only                1         0.0002   
86400                     2805      0.5063   
86400 only                2801      0.5056   
100800                    9140      1.6497   
100800 only               9137      1.6491   
108000                    1         0.0002   
108000 only               1         0.0002   
115200                    1         0.0002   
115200 only               1         0.0002   
129600                    6         0.0011   
129600 only               6         0.0011   
172800                    49        0.0088   
172800 only               49        0.0088   
216000                    4         0.0007   
216000 only               4         0.0007   
432000                    1         0.0002   
432000 only               1         0.0002   
604800                    2         0.0004   
864000                    2         0.0004   
864000 only               2         0.0004   
7776000                   2         0.0004   
7776000 only              2         0.0004   
None                      144581    26.0956  
None only                 140902    25.4316  

Certificate sig alg     Count     Percent 
-------------------------+---------+--------
None                      10359     1.8697   
ecdsa-with-SHA256         63100     11.389   
sha1WithRSAEncryption     29544     5.3324   
sha256WithRSAEncryption   477256    86.1405  
sha384WithRSAEncryption   5         0.0009   
sha512WithRSAEncryption   60        0.0108   

Certificate key size    Count     Percent 
-------------------------+---------+--------
ECDSA 256                 66442     11.9922  
ECDSA 384                 21        0.0038   
ECDSA 521                 1         0.0002   
RSA 1024                  21        0.0038   
RSA 2048                  479886    86.6151  
RSA 2049                  2         0.0004   
RSA 2056                  3         0.0005   
RSA 2058                  3         0.0005   
RSA 2084                  3         0.0005   
RSA 2086                  1         0.0002   
RSA 2096                  2         0.0004   
RSA 2432                  2         0.0004   
RSA 3072                  150       0.0271   
RSA 3073                  1         0.0002   
RSA 3076                  3         0.0005   
RSA 3096                  2         0.0004   
RSA 3248                  3         0.0005   
RSA 4048                  3         0.0005   
RSA 4056                  15        0.0027   
RSA 4069                  1         0.0002   
RSA 4086                  4         0.0007   
RSA 4092                  2         0.0004   
RSA 4094                  1         0.0002   
RSA 4095                  1         0.0002   
RSA 4096                  26364     4.7585   
RSA 4196                  1         0.0002   
RSA 8192                  9         0.0016   
RSA 8392                  1         0.0002   
RSA/ECDSA Dual Stack      18891     3.4097

OCSP stapling             Count     Percent 
-------------------------+---------+--------
Supported                 128586    23.2086  
Unsupported               425458    76.7914  

Supported Protocols       Count     Percent
-------------------------+---------+-------
SSL2                      17623     3.1808
SSL2 Only                 17        0.0031
SSL3                      98238     17.7311
SSL3 Only                 1159      0.2092
SSL3 or TLS1 Only         52628     9.4989
SSL3 or lower Only        1168      0.2108
TLS1                      543101    98.0249
TLS1 Only                 32939     5.9452
TLS1 or lower Only        68307     12.3288
TLS1.1                    473247    85.4169
TLS1.1 Only               208       0.0375
TLS1.1 or up Only         9606      1.7338
TLS1.2                    482460    87.0797
TLS1.2 Only               2594      0.4682
TLS1.2, 1.0 but not 1.1   8635      1.5585


Statistics from 589898 chains provided by 709652 hosts

Server provided chains    Count     Percent
-------------------------+---------+-------
complete                  529449    74.6068
incomplete                22333     3.147
untrusted                 157870    22.2461

Trusted chain statistics
========================

Chain length              Count     Percent
-------------------------+---------+-------
2                         8         0.0014
3                         587212    99.5447
4                         2665      0.4518
5                         13        0.0022

CA key size in chains     Count
-------------------------+---------
ECDSA 256                 63091     
ECDSA 384                 63090     
RSA 1024                  21        
RSA 2045                  2         
RSA 2048                  881842    
RSA 4096                  174433    

Chains with CA key        Count     Percent
-------------------------+---------+-------
ECDSA 256                 63091     10.6952
ECDSA 384                 63090     10.6951
RSA 1024                  19        0.0032
RSA 2045                  2         0.0003
RSA 2048                  526385    89.2332
RSA 4096                  173801    29.4629

Signature algorithm (ex. root) Count
------------------------------+---------
ecdsa-with-SHA384              63084     
sha1WithRSAEncryption          33756     
sha256WithRSAEncryption        339826    
sha384WithRSAEncryption        155860    
sha512WithRSAEncryption        55        

Eff. host cert chain LoS  Count     Percent
-------------------------+---------+-------
80                        33778     5.7261
112                       493007    83.575
128                       63113     10.699

Root CAs                                      Count     Percent
---------------------------------------------+---------+-------
(d6325660) COMODO RSA Certification Authority 138204    23.4285
(2c543cd1) GeoTrust Global CA                 95310     16.157
(eed8c118) COMODO ECC Certification Authority 63077     10.6929
(5ad8a5d6) GlobalSign Root CA                 56226     9.5315
(cbf06781) Go Daddy Root Certificate Authorit 49413     8.3765
(b204d74a) VeriSign Class 3 Public Primary Ce 30520     5.1738
(244b5494) DigiCert High Assurance EV Root CA 19387     3.2865
(2e4eed3c) thawte Primary Root CA             18858     3.1968
(653b494a) Baltimore CyberTrust Root          12557     2.1287
(2e5ac55d) DST Root CA X3                     12525     2.1232
(fc5a8f99) USERTrust RSA Certification Author 17514     2.969
(ae8153b9) StartCom Certification Authority   9654      1.6366
(3513523f) DigiCert Global Root CA            9633      1.633
(4bfab552) Starfield Root Certificate Authori 8780      1.4884


Scan performed between 18th of April and 1st of May 2016

November 2015 scan results

Number of servers which support TLS has grown by 1.3% since last month.

Cipher suites

Surprisingly, 3.2% more servers support just AES cipher suites now. At the same time we lost 3.7% market share of Camellia.

The good news is that RC4 support has dropped by 4.7%. Unfortunately, the amount of servers which default to RC4 is still rather high, at a 4% mark level.

Ciphersuites which are completely insecure have lost just 0.5%.

Essentially no change in server side vs client side cipher ordering, with just a small increase in the former.

Key exchange

Ciphersuites which provide forward secrecy are still growing, with ECDHE gaining 0.7% and support for ECDHE and DHE at the same time gaining 0.3%.

As usual, most of the gains are caused by the P-256 curve, with it increasing by 0.65%.

We’re now at 85% mark for servers which prefer forward secure ciphersuites, an increase of 1.11% since last month.

Hash and signature algorithms

Support for the obsolete RSA-MD5 signature algorithm continues to drop, but rather slowly, loosing just 1.1% since previous survey.

Fortunately, servers which are limited to just RSA-SHA1 signatures are also dropping, showing 0.3% fewer servers which do force this mechanism on clients. Support for stronger algorithms like SHA256 is still rather slow on the up tick, gaining just 0.7%.

Vulnerabilities

Little changes here, still 3.5% of servers vulnerable to insecure renegotiation attacks and just under 2% vulnerable to CRIME attack.

Certificates

Use of SHA-256 signatures in certificates continues its rise as de facto the signature standard, gaining 1.5% since last month.

This is also the first time when signatures with ECDSA certificates broke double digits, through an increase of 0.6%. We are less than 5% away from two most popular signature methods both using SHA-256.

Only minimal changes in the key sizes department, just that the ECDSA 256 bit keys have also increased by 0.6%, gaining a double digit market share.

At the same time, 2.6% of servers use configuration in which they support both of those public key standards.

Protocols

Little to no changes here. SSLv2 and SSLv3 are loosing, TLSv1.0 more or less stable, TLSv1.1 and TLSv1.2 gaining. All changes below 0.5% mark.

Results

SSL/TLS survey of 530912 websites from Alexa's top 1 million
Stats only from connections that did provide valid certificates
(or anonymous DH from servers that do also have valid certificate installed)


Supported Ciphers         Count     Percent
-------------------------+---------+-------
3DES                      457179    86.112
3DES Only                 577       0.1087
AES                       523844    98.6687
AES Only                  40463     7.6214
AES-CBC                   523220    98.5512
AES-CBC Only              10280     1.9363
AES-GCM                   398334    75.0283
AES-GCM Only              481       0.0906
CAMELLIA                  217685    41.0021
CAMELLIA Only             1         0.0002
CHACHA20                  67665     12.7451
CHACHA20 Only             2         0.0004
Insecure                  60479     11.3915
RC4                       191727    36.1128
RC4 Only                  977       0.184
RC4 Preferred             21462     4.0425
RC4 forced in TLS1.1+     11194     2.1084
x:FF 29 RC4 Only          1213      0.2285
x:FF 29 RC4 Preferred     23754     4.4742
x:FF 29 incompatible      400       0.0753
x:FF 35 RC4 Only          1476      0.278
x:FF 35 RC4 Preferred     23839     4.4902
x:FF 35 incompatible      402       0.0757
y:DHE-RSA-SEED-SHA        65003     12.2436
y:IDEA-CBC-SHA            59414     11.1909
y:SEED-SHA                76068     14.3278
z:ADH-AES128-GCM-SHA256   396       0.0746
z:ADH-AES128-SHA          744       0.1401
z:ADH-AES128-SHA256       292       0.055
z:ADH-AES256-GCM-SHA384   408       0.0768
z:ADH-AES256-SHA          756       0.1424
z:ADH-AES256-SHA256       293       0.0552
z:ADH-CAMELLIA128-SHA     374       0.0704
z:ADH-CAMELLIA256-SHA     382       0.072
z:ADH-DES-CBC-SHA         303       0.0571
z:ADH-DES-CBC3-SHA        756       0.1424
z:ADH-RC4-MD5             616       0.116
z:ADH-SEED-SHA            305       0.0574
z:AECDH-AES128-SHA        10719     2.019
z:AECDH-AES256-SHA        10755     2.0258
z:AECDH-DES-CBC3-SHA      10685     2.0126
z:AECDH-NULL-SHA          63        0.0119
z:AECDH-RC4-SHA           10125     1.9071
z:DES-CBC-MD5             11270     2.1228
z:DES-CBC-SHA             36559     6.8861
z:DES-CBC3-MD5            23236     4.3766
z:ECDHE-RSA-NULL-SHA      68        0.0128
z:EDH-RSA-DES-CBC-SHA     31274     5.8906
z:EXP-ADH-DES-CBC-SHA     203       0.0382
z:EXP-ADH-RC4-MD5         199       0.0375
z:EXP-DES-CBC-SHA         14643     2.7581
z:EXP-EDH-RSA-DES-CBC-SHA 11812     2.2249
z:EXP-RC2-CBC-MD5         17779     3.3488
z:EXP-RC4-MD5             18577     3.4991
z:EXP1024-DES-CBC-SHA     4531      0.8534
z:EXP1024-RC4-SHA         4613      0.8689
z:IDEA-CBC-MD5            2255      0.4247
z:NULL-MD5                237       0.0446
z:NULL-SHA                236       0.0445
z:NULL-SHA256             32        0.006
z:RC2-CBC-MD5             11512     2.1683
z:RC4-64-MD5              922       0.1737

Cipher ordering           Count     Percent
-------------------------+---------+-------
Client side               134022    25.2437
Server side               396890    74.7563

Supported Handshakes      Count     Percent
-------------------------+---------+-------
ADH                       896       0.1688
AECDH                     10782     2.0308
DHE                       289298    54.4908
ECDH                      3         0.0006
ECDHE                     425231    80.0944
ECDHE and DHE             223210    42.0427
RSA                       458647    86.3885

Supported PFS             Count     Percent  PFS Percent
-------------------------+---------+--------+-----------
DH,1024bits               159457    30.0345  55.1186
DH,1536bits               1         0.0002   0.0003
DH,2048bits               121879    22.9565  42.1292
DH,2236bits               14        0.0026   0.0048
DH,3072bits               108       0.0203   0.0373
DH,3092bits               1         0.0002   0.0003
DH,4096bits               7458      1.4048   2.578
DH,512bits                40        0.0075   0.0138
DH,6144bits               1         0.0002   0.0003
DH,768bits                439       0.0827   0.1517
DH,8192bits               2         0.0004   0.0007
ECDH,B-571,570bits        1680      0.3164   0.3951
ECDH,K-571,570bits        1         0.0002   0.0002
ECDH,P-192,192bits        11        0.0021   0.0026
ECDH,P-224,224bits        81        0.0153   0.019
ECDH,P-256,256bits        411892    77.582   96.8631
ECDH,P-384,384bits        3589      0.676    0.844
ECDH,P-521,521bits        9333      1.7579   2.1948
Prefer DH,1024bits        58262     10.9739  20.1391
Prefer DH,1536bits        1         0.0002   0.0003
Prefer DH,2048bits        10378     1.9547   3.5873
Prefer DH,2236bits        1         0.0002   0.0003
Prefer DH,3072bits        13        0.0024   0.0045
Prefer DH,4096bits        392       0.0738   0.1355
Prefer DH,768bits         66        0.0124   0.0228
Prefer ECDH,B-571,570bits 1478      0.2784   0.3476
Prefer ECDH,K-571,570bits 1         0.0002   0.0002
Prefer ECDH,P-224,224bits 78        0.0147   0.0183
Prefer ECDH,P-256,256bits 370937    69.8679  87.2319
Prefer ECDH,P-384,384bits 3291      0.6199   0.7739
Prefer ECDH,P-521,521bits 8426      1.5871   1.9815
Prefer PFS                453324    85.3859  0
Support PFS               491319    92.5425  0

Supported ECC curves      Count     Percent 
-------------------------+---------+--------
brainpoolP256r1           2073      0.3905   
brainpoolP384r1           2074      0.3906   
brainpoolP512r1           2074      0.3906   
prime192v1                1449      0.2729   
prime256v1                422425    79.5659  
prime256v1 Only           368568    69.4217  
secp160k1                 1406      0.2648   
secp160r1                 1411      0.2658   
secp160r2                 1406      0.2648   
secp192k1                 1423      0.268    
secp224k1                 1491      0.2808   
secp224r1                 4011      0.7555   
secp256k1                 3482      0.6559   
secp384r1                 54256     10.2194  
secp384r1 Only            444       0.0836   
secp521r1                 23612     4.4474   
secp521r1 Only            128       0.0241   
sect163k1                 1415      0.2665   
sect163k1 Only            2         0.0004   
sect163r1                 1413      0.2661   
sect163r2                 1409      0.2654   
sect193r1                 1409      0.2654   
sect193r2                 1407      0.265    
sect233k1                 1486      0.2799   
sect233r1                 1486      0.2799   
sect239k1                 1486      0.2799   
sect283k1                 3447      0.6493   
sect283k1 Only            2         0.0004   
sect283r1                 3442      0.6483   
sect409k1                 3444      0.6487   
sect409r1                 3443      0.6485   
sect571k1                 3454      0.6506   
sect571r1                 3454      0.6506   

Unsupported curve fallback     Count     Percent 
------------------------------+---------+--------
False                          69315     13.0558  
True                           299493    56.411   
order-specific                 82        0.0154   
unknown                        162022    30.5177  

ECC curve ordering        Count     Percent 
-------------------------+---------+--------
client                    5116      0.9636   
inconclusive-noecc        8         0.0015   
server                    417915    78.7164  
unknown                   107873    20.3184  

TLSv1.2 PFS supported sigalgs  Count     Percent 
------------------------------+---------+--------
ECDSA-SHA1                     39752     7.4875   
ECDSA-SHA1 Only                2         0.0004   
ECDSA-SHA224                   39755     7.4881   
ECDSA-SHA256                   53701     10.1149  
ECDSA-SHA384                   53712     10.1169  
ECDSA-SHA512                   53734     10.1211  
ECDSA-SHA512 Only              22        0.0041   
RSA-MD5                        164964    31.0718  
RSA-SHA1                       368019    69.3183  
RSA-SHA1 Only                  42674     8.0379   
RSA-SHA224                     303273    57.123   
RSA-SHA256                     332849    62.6938  
RSA-SHA256 Only                6204      1.1686   
RSA-SHA384                     304966    57.4419  
RSA-SHA384 Only                1         0.0002   
RSA-SHA512                     305210    57.4879  
RSA-SHA512 Only                277       0.0522   

TLSv1.2 PFS ordering           Count     Percent 
------------------------------+---------+--------
client                         233407    43.9634  
indeterminate                  45        0.0085   
intolerant                     4576      0.8619   
order-fallback                 8         0.0015   
server                         177923    33.5127  
unsupported                    21601     4.0687   

TLSv1.2 PFS sigalg fallback    Count     Percent 
------------------------------+---------+--------
ECDSA SHA1                     39724     7.4822   
ECDSA intolerant               116       0.0218   
ECDSA pfs-rsa-SHA512           13917     2.6213   
ECDSA soft-nopfs               3         0.0006   
RSA False                      163706    30.8349  
RSA SHA1                       176523    33.249   
RSA intolerant                 35829     6.7486   
RSA pfs-ecdsa-SHA512           27        0.0051   
RSA soft-nopfs                 1308      0.2464   

Renegotiation             Count     Percent 
-------------------------+---------+--------
False                     6621      1.2471   
insecure                  18673     3.5172   
secure                    505618    95.2357  

Compression               Count     Percent 
-------------------------+---------+--------
1 (zlib compression)      9772      1.8406   
False                     6621      1.2471   
NONE                      514519    96.9123  

TLS session ticket hint   Count     Percent 
-------------------------+---------+--------
1                         4         0.0008   
1 only                    4         0.0008   
2                         2         0.0004   
2 only                    2         0.0004   
10                        11        0.0021   
10 only                   11        0.0021   
15                        10        0.0019   
15 only                   10        0.0019   
30                        10        0.0019   
30 only                   9         0.0017   
60                        97        0.0183   
60 only                   90        0.017    
65                        2         0.0004   
65 only                   2         0.0004   
70                        6         0.0011   
100                       15        0.0028   
100 only                  15        0.0028   
120                       27        0.0051   
120 only                  27        0.0051   
128                       2         0.0004   
128 only                  2         0.0004   
150                       2         0.0004   
180                       41        0.0077   
180 only                  38        0.0072   
240                       5         0.0009   
240 only                  5         0.0009   
300                       244735    46.0971  
300 only                  240267    45.2555  
302                       3         0.0006   
302 only                  3         0.0006   
360                       2         0.0004   
360 only                  1         0.0002   
400                       8         0.0015   
400 only                  8         0.0015   
420                       124       0.0234   
420 only                  97        0.0183   
450                       1         0.0002   
450 only                  1         0.0002   
480                       13        0.0024   
480 only                  13        0.0024   
500                       3         0.0006   
500 only                  3         0.0006   
540                       1         0.0002   
540 only                  1         0.0002   
600                       26475     4.9867   
600 only                  26305     4.9547   
700                       1         0.0002   
700 only                  1         0.0002   
720                       1         0.0002   
720 only                  1         0.0002   
840                       1         0.0002   
840 only                  1         0.0002   
900                       878       0.1654   
900 only                  861       0.1622   
960                       2         0.0004   
960 only                  2         0.0004   
1200                      2334      0.4396   
1200 only                 2330      0.4389   
1320                      1         0.0002   
1320 only                 1         0.0002   
1500                      9         0.0017   
1500 only                 8         0.0015   
1800                      499       0.094    
1800 only                 490       0.0923   
1980                      1         0.0002   
1980 only                 1         0.0002   
2100                      1         0.0002   
2100 only                 1         0.0002   
2400                      8         0.0015   
2400 only                 8         0.0015   
2700                      10        0.0019   
2700 only                 10        0.0019   
3000                      26        0.0049   
3000 only                 26        0.0049   
3600                      573       0.1079   
3600 only                 560       0.1055   
3900                      3         0.0006   
3900 only                 3         0.0006   
4200                      1         0.0002   
5160                      1         0.0002   
5160 only                 1         0.0002   
5400                      13        0.0024   
5400 only                 6         0.0011   
6000                      179       0.0337   
6000 only                 179       0.0337   
7200                      15645     2.9468   
7200 only                 15623     2.9427   
10800                     3114      0.5865   
10800 only                3110      0.5858   
14400                     99        0.0186   
14400 only                99        0.0186   
18000                     8         0.0015   
18000 only                8         0.0015   
21600                     4849      0.9133   
21600 only                4637      0.8734   
25200                     1         0.0002   
25200 only                1         0.0002   
28800                     3555      0.6696   
28800 only                3543      0.6673   
36000                     1157      0.2179   
36000 only                1150      0.2166   
43200                     40        0.0075   
43200 only                40        0.0075   
60000                     1         0.0002   
60000 only                1         0.0002   
64800                     51789     9.7547   
64800 only                51762     9.7496   
72000                     29        0.0055   
72000 only                29        0.0055   
84600                     1         0.0002   
84600 only                1         0.0002   
86000                     39        0.0073   
86000 only                39        0.0073   
86400                     3482      0.6559   
86400 only                3471      0.6538   
100800                    10699     2.0152   
100800 only               10688     2.0131   
129600                    10        0.0019   
129600 only               10        0.0019   
172800                    9         0.0017   
172800 only               9         0.0017   
216000                    2         0.0004   
216000 only               2         0.0004   
432000                    2         0.0004   
432000 only               2         0.0004   
604800                    5         0.0009   
604800 only               3         0.0006   
864000                    3         0.0006   
864000 only               3         0.0006   
None                      165273    31.13    
None only                 160236    30.1813  

Certificate sig alg     Count     Percent 
-------------------------+---------+--------
None                      11419     2.1508   
ecdsa-with-SHA256         53709     10.1164  
sha1WithRSAEncryption     79229     14.9232  
sha256WithRSAEncryption   413158    77.8204  
sha384WithRSAEncryption   6         0.0011   
sha512WithRSAEncryption   33        0.0062   

Certificate key size    Count     Percent 
-------------------------+---------+--------
ECDSA 256                 53748     10.1237  
ECDSA 384                 12        0.0023   
ECDSA 521                 1         0.0002   
RSA 1024                  38        0.0072   
RSA 10240                 8         0.0015   
RSA 2048                  470388    88.6     
RSA 2049                  4         0.0008   
RSA 2056                  1         0.0002   
RSA 2058                  2         0.0004   
RSA 2064                  1         0.0002   
RSA 2084                  3         0.0006   
RSA 2096                  1         0.0002   
RSA 2408                  2         0.0004   
RSA 2432                  2         0.0004   
RSA 2480                  1         0.0002   
RSA 3071                  1         0.0002   
RSA 3072                  144       0.0271   
RSA 3096                  2         0.0004   
RSA 3120                  2         0.0004   
RSA 3248                  2         0.0004   
RSA 4042                  1         0.0002   
RSA 4048                  1         0.0002   
RSA 4056                  22        0.0041   
RSA 4069                  1         0.0002   
RSA 4086                  1         0.0002   
RSA 4092                  6         0.0011   
RSA 4094                  1         0.0002   
RSA 4096                  20509     3.863    
RSA 4098                  1         0.0002   
RSA 4196                  1         0.0002   
RSA 8192                  3         0.0006   
RSA/ECDSA Dual Stack      13986     2.6343

OCSP stapling             Count     Percent 
-------------------------+---------+--------
Supported                 115313    21.7198  
Unsupported               415599    78.2802  

Supported Protocols       Count     Percent
-------------------------+---------+-------
SSL2                      23492     4.4248
SSL2 Only                 19        0.0036
SSL3                      121502    22.8855
SSL3 Only                 470       0.0885
SSL3 or TLS1 Only         68017     12.8114
SSL3 or lower Only        487       0.0917
TLS1                      525297    98.9424
TLS1 Only                 40462     7.6212
TLS1 or lower Only        89960     16.9444
TLS1.1                    427273    80.4791
TLS1.1 Only               312       0.0588
TLS1.1 or up Only         4757      0.896
TLS1.2                    437543    82.4135
TLS1.2 Only               2067      0.3893
TLS1.2, 1.0 but not 1.1   11005     2.0728



Statistics from 566530 chains provided by 702674 hosts

Server provided chains    Count     Percent
-------------------------+---------+-------
complete                  500948    71.2917
incomplete                27324     3.8886
untrusted                 174402    24.8198

Trusted chain statistics
========================

Chain length              Count     Percent
-------------------------+---------+-------
2                         40        0.0071
3                         564250    99.5975
4                         2220      0.3919
5                         20        0.0035

CA key size in chains     Count
-------------------------+---------
ECDSA 256                 53700     
ECDSA 384                 53703     
RSA 1024                  38        
RSA 2045                  3         
RSA 2048                  886848    
RSA 4096                  140988    

Chains with CA key        Count     Percent
-------------------------+---------+-------
ECDSA 256                 53700     9.4788
ECDSA 384                 53703     9.4793
RSA 1024                  36        0.0064
RSA 2045                  3         0.0005
RSA 2048                  512489    90.4611
RSA 4096                  140488    24.798

Signature algorithm (ex. root) Count
------------------------------+---------
ecdsa-with-SHA384              53695     
sha1WithRSAEncryption          87476     
sha256WithRSAEncryption        301918    
sha384WithRSAEncryption        125587    
sha512WithRSAEncryption        74        

Eff. host cert chain LoS  Count     Percent
-------------------------+---------+-------
80                        87515     15.4475
112                       425304    75.0718
128                       53711     9.4807

Root CAs                                      Count     Percent
---------------------------------------------+---------+-------
(d6325660) COMODO RSA Certification Authority 116038    20.4822
(2c543cd1) GeoTrust Global CA                 109648    19.3543
(eed8c118) COMODO ECC Certification Authority 53687     9.4765
(cbf06781) Go Daddy Root Certificate Authorit 48182     8.5048
(5ad8a5d6) GlobalSign Root CA                 44132     7.7899
(b204d74a) VeriSign Class 3 Public Primary Ce 32386     5.7166
(244b5494) DigiCert High Assurance EV Root CA 26649     4.7039
(2e4eed3c) thawte Primary Root CA             22839     4.0314
(157753a5) AddTrust External CA Root          21671     3.8252
(653b494a) Baltimore CyberTrust Root          12055     2.1279
(fc5a8f99) USERTrust RSA Certification Author 9450      1.668
(ae8153b9) StartCom Certification Authority   9327      1.6463
(4bfab552) Starfield Root Certificate Authori 9162      1.6172
(3513523f) DigiCert Global Root CA            8636      1.5244

Scan performed between 22nd November and 3rd of December 2015

October 2015 scan results

Because the previous two months were published with a much longer delay than usual (sorry about that, will explain myself in future post) the following analysis compares this month’s results to July, not September.

Number of servers supporting TLS has grown by over 4% during those 3 months. The most profound change during that time was decommissioning of over 10% of SHA-1 using certificates. Rest of changes is just continuation of established trends.

Cipher suites

3DES continues the somewhat surprising increase in support, gaining another 1.6%. AES in general and AES in CBC mode in particular have shown little change, gaining less than half a percent in use. AES-GCM has grown by over 5% at the same time. Similarly to AES, Camellia and ChaCha20 support is relatively stable, both gaining about 0.2% each.

Use of insecure ciphers has decreased somewhat, loosing nearly 3% since last publication of results. RC4 has lost a staggering 10% of market share, for the first time since scans began falling below Camellia levels.

Unfortunately, there are still over 1100 servers which require use of RC4 for a successful connection, or over 1600 if you’re using Firefox 35.

Use of server side cipher ordering also plateaued, with just 0.2% more servers opting to ignore client presented order of ciphers for negotiation.

Key exchange

Support for the modern ECDHE key exchange has grown by nearly 5% during that time, reaching over 79% of servers.

The older and slower DHE key exchange has lost 1.6% of support among the servers.

The insecure ADH and AECDH key exchanges have also fallen, the former to a level of below 1000 servers, the latter by 1.5% to just over 2.1%.

Most of the increases in the ECDHE support are due to P-256 NIST curve, gaining nearly 4.5%.

We also see very good changes in DHE support, use of 1024 bit prime has fallen by 9% while use of 2048 bit prime has risen by 8%. For ciphersuites effectively negotiated, the changes are a bit less pronounced, with just 4.1% less servers picking a DHE ciphersuite with 1024 bit prime, making connections to 11.4% of servers a bit less secure. While preference for 2048 bit DH risen by just 1.12%.

Overall, 1.6% more servers support ciphersuites that provide Forward Secrecy while a very nice 4.4% more actually prefer them.

As usual, the support for ECDHE is mostly driven by P-256 (a.k.a. prime256v1), with it gaining 4.8% more market share. One other curve has finally risen to the double digit level (though just barely), with an increase of 0.2% – P-384, a.k.a. secp384r1.

Hash and signature algorithms

Support for SHA256 with RSA certificates has grown by nearly 5%, stronger hashes have seen smaller changes with SHA384 and SHA512 gaining only 3.8%.

Support for the insecure MD5 is also increasing, thankfully at a slower rate, with it gaining only 0.7%. Number of servers that support only the rather weak SHA1 is decreasing though, over those 3 months it has fallen by 1.2%.

Vulnerabilities

Support for secure renegotiation is still missing in 3.6% of servers, loosing just over half a percent. Similarly, 1.2% of servers are vulnerable to the CRIME attack, a change of only 0.2%.

Certificates

Certificates used by servers have seen comparatively the biggest change. SHA-1 use has fallen by nearly 13%! The switch was shared by SHA-256 with RSA (increase by just over 12%) and SHA-256 with ECDSA (increase by 2.6%).

We’ve also finally reached a “less than 100 servers with 1024 bit RSA keys” milestone. Use of 2048 bit RSA has fallen by just one percent, at the same time use of 256 bit ECDSA has grown by 2.67%.

The list of CA’s with more than 1% of servers have also shrunk by 2 positions.

Protocols

Still over half a thousand of servers support only the insecure SSLv2 and SSLv3 protocols.

At the same time, more than 4 in 5 servers support the newest and most secure TLS v1.2 protocol.

Results

SSL/TLS survey of 523658 websites from Alexa's top 1 million
Stats only from connections that did provide valid certificates
(or anonymous DH from servers that do also have valid certificate installed)


Supported Ciphers         Count     Percent
-------------------------+---------+-------
3DES                      450366    86.0038
3DES Only                 598       0.1142
AES                       516026    98.5426
AES Only                  22924     4.3777
AES-CBC                   515568    98.4551
AES-CBC Only              10087     1.9263
AES-GCM                   388464    74.1828
AES-GCM Only              378       0.0722
CAMELLIA                  234209    44.7256
CAMELLIA Only             3         0.0006
CHACHA20                  64701     12.3556
CHACHA20 Only             1         0.0002
Insecure                  61963     11.8327
RC4                       213861    40.8398
RC4 Only                  1101      0.2103
RC4 Preferred             22873     4.3679
RC4 forced in TLS1.1+     11792     2.2519
x:FF 29 RC4 Only          1377      0.263
x:FF 29 RC4 Preferred     26049     4.9744
x:FF 29 incompatible      312       0.0596
x:FF 35 RC4 Only          1656      0.3162
x:FF 35 RC4 Preferred     26149     4.9935
x:FF 35 incompatible      315       0.0602
y:DHE-RSA-SEED-SHA        84215     16.0821
y:IDEA-CBC-SHA            78851     15.0577
y:SEED-SHA                95873     18.3083
z:ADH-AES128-GCM-SHA256   395       0.0754
z:ADH-AES128-SHA          756       0.1444
z:ADH-AES128-SHA256       295       0.0563
z:ADH-AES256-GCM-SHA384   403       0.077
z:ADH-AES256-SHA          764       0.1459
z:ADH-AES256-SHA256       297       0.0567
z:ADH-CAMELLIA128-SHA     380       0.0726
z:ADH-CAMELLIA256-SHA     388       0.0741
z:ADH-DES-CBC-SHA         305       0.0582
z:ADH-DES-CBC3-SHA        775       0.148
z:ADH-RC4-MD5             638       0.1218
z:ADH-SEED-SHA            313       0.0598
z:AECDH-AES128-SHA        11266     2.1514
z:AECDH-AES256-SHA        11290     2.156
z:AECDH-DES-CBC3-SHA      11231     2.1447
z:AECDH-NULL-SHA          59        0.0113
z:AECDH-RC4-SHA           10599     2.024
z:DES-CBC-MD5             11791     2.2517
z:DES-CBC-SHA             36853     7.0376
z:DES-CBC3-MD5            24006     4.5843
z:ECDHE-RSA-NULL-SHA      63        0.012
z:EDH-RSA-DES-CBC-SHA     31633     6.0408
z:EXP-ADH-DES-CBC-SHA     208       0.0397
z:EXP-ADH-RC4-MD5         205       0.0391
z:EXP-DES-CBC-SHA         15360     2.9332
z:EXP-EDH-RSA-DES-CBC-SHA 12356     2.3596
z:EXP-RC2-CBC-MD5         18735     3.5777
z:EXP-RC4-MD5             19564     3.736
z:EXP1024-DES-CBC-SHA     4870      0.93
z:EXP1024-RC4-SHA         4967      0.9485
z:IDEA-CBC-MD5            2349      0.4486
z:NULL-MD5                227       0.0433
z:NULL-SHA                232       0.0443
z:NULL-SHA256             29        0.0055
z:RC2-CBC-MD5             12033     2.2979
z:RC4-64-MD5              968       0.1849

Cipher ordering           Count     Percent
-------------------------+---------+-------
Client side               134694    25.7217
Server side               388964    74.2783

Supported Handshakes      Count     Percent
-------------------------+---------+-------
ADH                       903       0.1724
AECDH                     11321     2.1619
DHE                       286818    54.772
ECDH                      3         0.0006
ECDHE                     415495    79.3447
ECDHE and DHE             219028    41.8265
RSA                       471189    89.9803

Supported PFS             Count     Percent  PFS Percent
-------------------------+---------+--------+-----------
DH,1024bits               162798    31.0886  56.76
DH,1536bits               1         0.0002   0.0003
DH,2048bits               116370    22.2225  40.5728
DH,2236bits               11        0.0021   0.0038
DH,2432bits               1         0.0002   0.0003
DH,3072bits               109       0.0208   0.038
DH,3092bits               1         0.0002   0.0003
DH,4094bits               1         0.0002   0.0003
DH,4096bits               7102      1.3562   2.4761
DH,512bits                43        0.0082   0.015
DH,768bits                450       0.0859   0.1569
DH,8192bits               2         0.0004   0.0007
ECDH,B-571,570bits        1628      0.3109   0.3918
ECDH,K-163,163bits        1         0.0002   0.0002
ECDH,K-571,570bits        1         0.0002   0.0002
ECDH,P-192,192bits        8         0.0015   0.0019
ECDH,P-224,224bits        71        0.0136   0.0171
ECDH,P-256,256bits        402982    76.9552  96.9884
ECDH,P-384,384bits        2860      0.5462   0.6883
ECDH,P-521,521bits        8826      1.6855   2.1242
Prefer DH,1024bits        59986     11.4552  20.9143
Prefer DH,1536bits        1         0.0002   0.0003
Prefer DH,2048bits        9957      1.9014   3.4715
Prefer DH,3072bits        13        0.0025   0.0045
Prefer DH,4096bits        345       0.0659   0.1203
Prefer DH,768bits         65        0.0124   0.0227
Prefer ECDH,B-571,570bits 1429      0.2729   0.3439
Prefer ECDH,K-163,163bits 1         0.0002   0.0002
Prefer ECDH,K-571,570bits 1         0.0002   0.0002
Prefer ECDH,P-224,224bits 55        0.0105   0.0132
Prefer ECDH,P-256,256bits 358890    68.5352  86.3765
Prefer ECDH,P-384,384bits 2659      0.5078   0.64
Prefer ECDH,P-521,521bits 7931      1.5145   1.9088
Prefer PFS                441333    84.2789  0
Support PFS               483285    92.2902  0

Supported ECC curves      Count     Percent 
-------------------------+---------+--------
brainpoolP256r1           1825      0.3485   
brainpoolP384r1           1827      0.3489   
brainpoolP512r1           1828      0.3491   
prime192v1                1461      0.279    
prime256v1                413390    78.9427  
prime256v1 Only           360620    68.8656  
secp160k1                 1415      0.2702   
secp160r1                 1422      0.2716   
secp160r2                 1414      0.27     
secp192k1                 1433      0.2737   
secp224k1                 1489      0.2843   
secp224r1                 3846      0.7344   
secp256k1                 3218      0.6145   
secp384r1                 53089     10.1381  
secp384r1 Only            364       0.0695   
secp521r1                 22417     4.2808   
secp521r1 Only            125       0.0239   
sect163k1                 1415      0.2702   
sect163k1 Only            1         0.0002   
sect163r1                 1414      0.27     
sect163r2                 1414      0.27     
sect193r1                 1412      0.2696   
sect193r2                 1412      0.2696   
sect233k1                 1482      0.283    
sect233r1                 1481      0.2828   
sect239k1                 1481      0.2828   
sect283k1                 3187      0.6086   
sect283r1                 3187      0.6086   
sect409k1                 3189      0.609    
sect409r1                 3189      0.609    
sect571k1                 3201      0.6113   
sect571r1                 3201      0.6113   

Unsupported curve fallback     Count     Percent 
------------------------------+---------+--------
False                          70006     13.3686  
True                           291129    55.5953  
order-specific                 72        0.0137   
unknown                        162451    31.0223  

ECC curve ordering        Count     Percent 
-------------------------+---------+--------
client                    4674      0.8926   
inconclusive-noecc        10        0.0019   
server                    409225    78.1474  
unknown                   109749    20.9581  

TLSv1.2 PFS supported sigalgs  Count     Percent 
------------------------------+---------+--------
ECDSA-SHA1                     38366     7.3265   
ECDSA-SHA1 Only                3         0.0006   
ECDSA-SHA224                   38357     7.3248   
ECDSA-SHA256                   49346     9.4233   
ECDSA-SHA384                   49344     9.4229   
ECDSA-SHA512                   49347     9.4235   
ECDSA-SHA512 Only              3         0.0006   
RSA-MD5                        168481    32.1739  
RSA-SHA1                       361209    68.978   
RSA-SHA1 Only                  43815     8.3671   
RSA-SHA224                     296284    56.5797  
RSA-SHA256                     324294    61.9286  
RSA-SHA256 Only                5869      1.1208   
RSA-SHA384                     297506    56.813   
RSA-SHA384 Only                1         0.0002   
RSA-SHA512                     297620    56.8348  
RSA-SHA512 Only                137       0.0262   

TLSv1.2 PFS ordering           Count     Percent 
------------------------------+---------+--------
client                         238653    45.5742  
indeterminate                  202       0.0386   
intolerant                     4295      0.8202   
order-fallback                 10        0.0019   
server                         163641    31.2496  
unsupported                    21408     4.0882   

TLSv1.2 PFS sigalg fallback    Count     Percent 
------------------------------+---------+--------
ECDSA SHA1                     38349     7.3233   
ECDSA intolerant               24        0.0046   
ECDSA pfs-rsa-SHA512           10983     2.0974   
ECDSA soft-nopfs               1         0.0002   
RSA False                      167225    31.934   
RSA SHA1                       166732    31.8399  
RSA intolerant                 34038     6.5      
RSA pfs-ecdsa-SHA512           5         0.001    
RSA soft-nopfs                 1316      0.2513   

Renegotiation             Count     Percent 
-------------------------+---------+--------
False                     6661      1.272    
insecure                  19263     3.6785   
secure                    497734    95.0494  

Compression               Count     Percent 
-------------------------+---------+--------
1 (zlib compression)      9887      1.8881   
False                     6661      1.272    
NONE                      507110    96.8399  

TLS session ticket hint   Count     Percent 
-------------------------+---------+--------
1                         2         0.0004   
1 only                    2         0.0004   
2                         2         0.0004   
2 only                    2         0.0004   
5                         2         0.0004   
5 only                    2         0.0004   
10                        8         0.0015   
10 only                   8         0.0015   
15                        9         0.0017   
15 only                   9         0.0017   
30                        10        0.0019   
30 only                   9         0.0017   
60                        96        0.0183   
60 only                   89        0.017    
65                        1         0.0002   
65 only                   1         0.0002   
70                        7         0.0013   
75                        1         0.0002   
75 only                   1         0.0002   
100                       18        0.0034   
100 only                  18        0.0034   
120                       26        0.005    
120 only                  26        0.005    
128                       3         0.0006   
128 only                  3         0.0006   
150                       2         0.0004   
180                       42        0.008    
180 only                  39        0.0074   
200                       1         0.0002   
200 only                  1         0.0002   
240                       12        0.0023   
240 only                  12        0.0023   
300                       242606    46.3291  
300 only                  238057    45.4604  
302                       3         0.0006   
302 only                  3         0.0006   
360                       2         0.0004   
360 only                  1         0.0002   
400                       8         0.0015   
400 only                  8         0.0015   
420                       119       0.0227   
420 only                  88        0.0168   
480                       12        0.0023   
480 only                  12        0.0023   
500                       5         0.001    
500 only                  5         0.001    
540                       1         0.0002   
540 only                  1         0.0002   
600                       25719     4.9114   
600 only                  25574     4.8837   
700                       1         0.0002   
700 only                  1         0.0002   
720                       2         0.0004   
720 only                  2         0.0004   
840                       1         0.0002   
840 only                  1         0.0002   
900                       781       0.1491   
900 only                  766       0.1463   
960                       2         0.0004   
960 only                  2         0.0004   
1200                      2230      0.4259   
1200 only                 2222      0.4243   
1320                      1         0.0002   
1320 only                 1         0.0002   
1500                      10        0.0019   
1500 only                 9         0.0017   
1800                      490       0.0936   
1800 only                 476       0.0909   
2100                      1         0.0002   
2100 only                 1         0.0002   
2400                      8         0.0015   
2400 only                 8         0.0015   
2700                      8         0.0015   
2700 only                 8         0.0015   
3000                      23        0.0044   
3000 only                 23        0.0044   
3600                      575       0.1098   
3600 only                 566       0.1081   
3900                      1         0.0002   
3900 only                 1         0.0002   
4100                      1         0.0002   
4100 only                 1         0.0002   
4200                      1         0.0002   
5160                      1         0.0002   
5160 only                 1         0.0002   
5400                      20        0.0038   
5400 only                 8         0.0015   
6000                      66        0.0126   
6000 only                 66        0.0126   
7200                      14981     2.8608   
7200 only                 14963     2.8574   
10800                     2576      0.4919   
10800 only                2570      0.4908   
14400                     102       0.0195   
14400 only                102       0.0195   
18000                     7         0.0013   
18000 only                7         0.0013   
21600                     4999      0.9546   
21600 only                4999      0.9546   
25200                     1         0.0002   
25200 only                1         0.0002   
28800                     2018      0.3854   
28800 only                1601      0.3057   
36000                     1153      0.2202   
36000 only                1144      0.2185   
43200                     34        0.0065   
43200 only                34        0.0065   
60000                     1         0.0002   
60000 only                1         0.0002   
64800                     53897     10.2924  
64800 only                53896     10.2922  
72000                     16        0.0031   
72000 only                16        0.0031   
84600                     1         0.0002   
84600 only                1         0.0002   
86000                     39        0.0074   
86000 only                39        0.0074   
86400                     3516      0.6714   
86400 only                3512      0.6707   
100800                    10300     1.9669   
100800 only               10290     1.965    
129600                    9         0.0017   
129600 only               9         0.0017   
172800                    6         0.0011   
172800 only               6         0.0011   
216000                    1         0.0002   
216000 only               1         0.0002   
432000                    2         0.0004   
432000 only               2         0.0004   
604800                    1         0.0002   
864000                    4         0.0008   
864000 only               4         0.0008   
None                      162322    30.9977  
None only                 157058    29.9925  

Certificate sig alg     Count     Percent 
-------------------------+---------+--------
None                      11981     2.2879   
ecdsa-with-SHA256         49307     9.4159   
sha1WithRSAEncryption     86227     16.4663  
sha256WithRSAEncryption   399420    76.275   
sha384WithRSAEncryption   6         0.0011   
sha512WithRSAEncryption   28        0.0053   

Certificate key size    Count     Percent 
-------------------------+---------+--------
ECDSA 256                 49343     9.4228   
ECDSA 384                 15        0.0029   
RSA 1024                  56        0.0107   
RSA 10240                 8         0.0015   
RSA 2047                  1         0.0002   
RSA 2048                  464934    88.7858  
RSA 2049                  4         0.0008   
RSA 2056                  4         0.0008   
RSA 2058                  2         0.0004   
RSA 2064                  2         0.0004   
RSA 2084                  4         0.0008   
RSA 2096                  2         0.0004   
RSA 2408                  2         0.0004   
RSA 2432                  1         0.0002   
RSA 2480                  1         0.0002   
RSA 3071                  1         0.0002   
RSA 3072                  127       0.0243   
RSA 3096                  2         0.0004   
RSA 3248                  2         0.0004   
RSA 4042                  1         0.0002   
RSA 4048                  1         0.0002   
RSA 4056                  25        0.0048   
RSA 4069                  3         0.0006   
RSA 4086                  2         0.0004   
RSA 4092                  6         0.0011   
RSA 4094                  1         0.0002   
RSA 4096                  20149     3.8477   
RSA 4098                  1         0.0002   
RSA 8192                  4         0.0008   
RSA/ECDSA Dual Stack      11039     2.1081

OCSP stapling             Count     Percent 
-------------------------+---------+--------
Supported                 113302    21.6366  
Unsupported               410356    78.3634  

Supported Protocols       Count     Percent
-------------------------+---------+-------
SSL2                      24244     4.6297
SSL2 Only                 19        0.0036
SSL3                      122263    23.3479
SSL3 Only                 484       0.0924
SSL3 or TLS1 Only         69496     13.2713
SSL3 or lower Only        503       0.0961
TLS1                      518406    98.9971
TLS1 Only                 41584     7.9411
TLS1 or lower Only        92178     17.6027
TLS1.1                    418156    79.8529
TLS1.1 Only               267       0.051
TLS1.1 or up Only         4492      0.8578
TLS1.2                    428200    81.7709
TLS1.2 Only               1845      0.3523
TLS1.2, 1.0 but not 1.1   10863     2.0744



Statistics from 549280 chains provided by 697275 hosts

Server provided chains    Count     Percent
-------------------------+---------+-------
complete                  487661    69.9381
incomplete                27391     3.9283
untrusted                 182223    26.1336

Trusted chain statistics
========================

Chain length              Count     Percent
-------------------------+---------+-------
2                         114       0.0208
3                         547038    99.5918
4                         2101      0.3825
5                         27        0.0049

CA key size in chains     Count
-------------------------+---------
ECDSA 256                 48991     
ECDSA 384                 48992     
RSA 1024                  101       
RSA 2045                  3         
RSA 2048                  865095    
RSA 4096                  137419    

Chains with CA key        Count     Percent
-------------------------+---------+-------
ECDSA 256                 48991     8.9191
ECDSA 384                 48992     8.9193
RSA 1024                  99        0.018
RSA 2045                  3         0.0005
RSA 2048                  499889    91.008
RSA 4096                  136911    24.9255

Signature algorithm (ex. root) Count
------------------------------+---------
ecdsa-with-SHA384              48986     
sha1WithRSAEncryption          92825     
sha256WithRSAEncryption        287083    
sha384WithRSAEncryption        122355    
sha512WithRSAEncryption        72        

Eff. host cert chain LoS  Count     Percent
-------------------------+---------+-------
80                        92922     16.9171
112                       407358    74.1622
128                       49000     8.9208

Root CAs                                      Count     Percent
---------------------------------------------+---------+-------
(d6325660) COMODO RSA Certification Authority 113492    20.662
(2c543cd1) GeoTrust Global CA                 107601    19.5895
(eed8c118) COMODO ECC Certification Authority 48977     8.9166
(cbf06781) Go Daddy Root Certificate Authorit 47939     8.7276
(5ad8a5d6) GlobalSign Root CA                 44123     8.0329
(b204d74a) VeriSign Class 3 Public Primary Ce 29359     5.345
(244b5494) DigiCert High Assurance EV Root CA 25999     4.7333
(2e4eed3c) thawte Primary Root CA             23372     4.255
(157753a5) AddTrust External CA Root          20188     3.6754
(653b494a) Baltimore CyberTrust Root          12053     2.1943
(ae8153b9) StartCom Certification Authority   9139      1.6638
(fc5a8f99) USERTrust RSA Certification Author 8775      1.5975
(3513523f) DigiCert Global Root CA            8281      1.5076
(4bfab552) Starfield Root Certificate Authori 8226      1.4976
(480720ec) GeoTrust Primary Certification Aut 5570      1.0141


Scan performed between 19th of October and 9th of November 2015

September 2015 scan results

(I have declared “analysis bankruptcy”, only raw results available for this month. Sorry! 🙇)

SSL/TLS survey of 514491 websites from Alexa's top 1 million
Stats only from connections that did provide valid certificates
(or anonymous DH from servers that do also have valid certificate installed)


Supported Ciphers         Count     Percent
-------------------------+---------+-------
3DES                      441032    85.722
3DES Only                 662       0.1287
AES                       506240    98.3963
AES Only                  20155     3.9175
AES-CBC                   506132    98.3753
AES-CBC Only              9532      1.8527
AES-GCM                   372880    72.4755
AES-GCM Only              53        0.0103
CAMELLIA                  228600    44.4323
CAMELLIA Only             1         0.0002
CHACHA20                  63632     12.368
CHACHA20 Only             1         0.0002
Insecure                  64742     12.5837
RC4                       231507    44.9973
RC4 Only                  1252      0.2433
RC4 Preferred             27685     5.381
RC4 forced in TLS1.1+     15710     3.0535
x:FF 29 RC4 Only          1532      0.2978
x:FF 29 RC4 Preferred     31430     6.109
x:FF 29 incompatible      137       0.0266
x:FF 35 RC4 Only          1845      0.3586
x:FF 35 RC4 Preferred     31550     6.1323
x:FF 35 incompatible      138       0.0268
y:DHE-RSA-SEED-SHA        86011     16.7177
y:IDEA-CBC-SHA            78923     15.34
y:SEED-SHA                96111     18.6808
z:ADH-AES128-GCM-SHA256   333       0.0647
z:ADH-AES128-SHA          745       0.1448
z:ADH-AES128-SHA256       236       0.0459
z:ADH-AES256-GCM-SHA384   343       0.0667
z:ADH-AES256-SHA          749       0.1456
z:ADH-AES256-SHA256       236       0.0459
z:ADH-CAMELLIA128-SHA     344       0.0669
z:ADH-CAMELLIA256-SHA     350       0.068
z:ADH-DES-CBC-SHA         321       0.0624
z:ADH-DES-CBC3-SHA        759       0.1475
z:ADH-RC4-MD5             621       0.1207
z:ADH-SEED-SHA            272       0.0529
z:AECDH-AES128-SHA        12374     2.4051
z:AECDH-AES256-SHA        12403     2.4107
z:AECDH-DES-CBC3-SHA      12331     2.3967
z:AECDH-NULL-SHA          55        0.0107
z:AECDH-RC4-SHA           11656     2.2655
z:DES-CBC-MD5             12201     2.3715
z:DES-CBC-SHA             37676     7.323
z:DES-CBC3-MD5            24906     4.8409
z:ECDHE-RSA-NULL-SHA      59        0.0115
z:EDH-RSA-DES-CBC-SHA     32341     6.286
z:EXP-ADH-DES-CBC-SHA     225       0.0437
z:EXP-ADH-RC4-MD5         222       0.0431
z:EXP-DES-CBC-SHA         16253     3.159
z:EXP-EDH-RSA-DES-CBC-SHA 13136     2.5532
z:EXP-RC2-CBC-MD5         19785     3.8455
z:EXP-RC4-MD5             20799     4.0426
z:EXP1024-DES-CBC-SHA     5124      0.9959
z:EXP1024-RC4-SHA         5211      1.0128
z:IDEA-CBC-MD5            2368      0.4603
z:NULL-MD5                228       0.0443
z:NULL-SHA                231       0.0449
z:NULL-SHA256             22        0.0043
z:RC2-CBC-MD5             12471     2.4239
z:RC4-64-MD5              1000      0.1944

Cipher ordering           Count     Percent
-------------------------+---------+-------
Client side               131154    25.492
Server side               383337    74.508

Supported Handshakes      Count     Percent
-------------------------+---------+-------
ADH                       872       0.1695
AECDH                     12430     2.416
DHE                       282349    54.8793
ECDH                      3         0.0006
ECDHE                     400761    77.8947
ECDHE and DHE             210872    40.9865
RSA                       466026    90.58

Supported PFS             Count     Percent  PFS Percent
-------------------------+---------+--------+-----------
DH,1024bits               176947    34.3926  62.6696
DH,1536bits               1         0.0002   0.0004
DH,2048bits               97579     18.9661  34.5597
DH,2236bits               10        0.0019   0.0035
DH,2560bits               1         0.0002   0.0004
DH,3072bits               1027      0.1996   0.3637
DH,3092bits               1         0.0002   0.0004
DH,4096bits               6303      1.2251   2.2323
DH,512bits                53        0.0103   0.0188
DH,768bits                502       0.0976   0.1778
DH,8192bits               1         0.0002   0.0004
ECDH,B-163,163bits        1         0.0002   0.0002
ECDH,B-571,570bits        1514      0.2943   0.3778
ECDH,K-163,163bits        1         0.0002   0.0002
ECDH,K-571,570bits        1         0.0002   0.0002
ECDH,P-192,192bits        2         0.0004   0.0005
ECDH,P-224,224bits        89        0.0173   0.0222
ECDH,P-256,256bits        389270    75.6612  97.1327
ECDH,P-384,384bits        2668      0.5186   0.6657
ECDH,P-521,521bits        8073      1.5691   2.0144
Prefer DH,1024bits        63712     12.3835  22.565
Prefer DH,1536bits        1         0.0002   0.0004
Prefer DH,2048bits        9342      1.8158   3.3087
Prefer DH,2236bits        1         0.0002   0.0004
Prefer DH,3072bits        14        0.0027   0.005
Prefer DH,4096bits        342       0.0665   0.1211
Prefer DH,768bits         102       0.0198   0.0361
Prefer ECDH,B-163,163bits 1         0.0002   0.0002
Prefer ECDH,B-571,570bits 1305      0.2536   0.3256
Prefer ECDH,K-163,163bits 1         0.0002   0.0002
Prefer ECDH,K-571,570bits 1         0.0002   0.0002
Prefer ECDH,P-224,224bits 55        0.0107   0.0137
Prefer ECDH,P-256,256bits 337269    65.5539  84.1571
Prefer ECDH,P-384,384bits 2525      0.4908   0.6301
Prefer ECDH,P-521,521bits 7266      1.4123   1.8131
Prefer PFS                421937    82.0106  0
Support PFS               472238    91.7874  0

Supported ECC curves      Count     Percent 
-------------------------+---------+--------
brainpoolP256r1           1285      0.2498   
brainpoolP384r1           1285      0.2498   
brainpoolP512r1           1285      0.2498   
prime192v1                1409      0.2739   
prime256v1                399379    77.626   
prime256v1 Only           346484    67.345   
secp160k1                 1372      0.2667   
secp160r1                 1376      0.2674   
secp160r2                 1372      0.2667   
secp192k1                 1393      0.2708   
secp224k1                 1466      0.2849   
secp224r1                 3478      0.676    
secp224r1 Only            2         0.0004   
secp256k1                 2664      0.5178   
secp384r1                 53002     10.3018  
secp384r1 Only            342       0.0665   
secp521r1                 22491     4.3715   
secp521r1 Only            118       0.0229   
sect163k1                 1376      0.2674   
sect163k1 Only            2         0.0004   
sect163r1                 1374      0.2671   
sect163r2                 1375      0.2673   
sect163r2 Only            1         0.0002   
sect193r1                 1374      0.2671   
sect193r2                 1374      0.2671   
sect233k1                 1460      0.2838   
sect233r1                 1458      0.2834   
sect239k1                 1458      0.2834   
sect283k1                 2637      0.5125   
sect283r1                 2637      0.5125   
sect409k1                 2637      0.5125   
sect409r1                 2637      0.5125   
sect571k1                 2650      0.5151   
sect571r1                 2650      0.5151   

Unsupported curve fallback     Count     Percent 
------------------------------+---------+--------
False                          69342     13.4778  
True                           279091    54.246   
order-specific                 247       0.048    
unknown                        165811    32.2282  

ECC curve ordering        Count     Percent 
-------------------------+---------+--------
client                    4128      0.8023   
inconclusive-noecc        10        0.0019   
server                    395723    76.9154  
unknown                   114630    22.2803  

TLSv1.2 PFS supported sigalgs  Count     Percent 
------------------------------+---------+--------
ECDSA-SHA1                     36846     7.1616   
ECDSA-SHA1 Only                3         0.0006   
ECDSA-SHA224                   36847     7.1618   
ECDSA-SHA256                   36861     7.1646   
ECDSA-SHA384                   36862     7.1648   
ECDSA-SHA512                   36877     7.1677   
ECDSA-SHA512 Only              15        0.0029   
RSA-MD5                        169404    32.9265  
RSA-SHA1                       349277    67.8879  
RSA-SHA1 Only                  46373     9.0134   
RSA-SHA224                     283789    55.1592  
RSA-SHA256                     309288    60.1153  
RSA-SHA256 Only                5302      1.0305   
RSA-SHA384                     284974    55.3895  
RSA-SHA384 Only                1         0.0002   
RSA-SHA512                     285175    55.4286  
RSA-SHA512 Only                218       0.0424   

TLSv1.2 PFS ordering           Count     Percent 
------------------------------+---------+--------
client                         247485    48.1029  
indeterminate                  113       0.022    
intolerant                     3917      0.7613   
order-fallback                 6         0.0012   
server                         141461    27.4953  
unsupported                    22160     4.3072   

TLSv1.2 PFS sigalg fallback    Count     Percent 
------------------------------+---------+--------
ECDSA SHA1                     36832     7.1589   
ECDSA intolerant               63        0.0122   
ECDSA pfs-rsa-SHA512           1         0.0002   
RSA False                      168019    32.6573  
RSA SHA1                       154614    30.0518  
RSA intolerant                 32671     6.3502   
RSA pfs-ecdsa-SHA512           1         0.0002   
RSA soft-nopfs                 1437      0.2793   

Renegotiation             Count     Percent 
-------------------------+---------+--------
False                     6340      1.2323   
insecure                  19961     3.8798   
secure                    488190    94.888   

Compression               Count     Percent 
-------------------------+---------+--------
1 (zlib compression)      10392     2.0199   
False                     6340      1.2323   
NONE                      497759    96.7479  

TLS session ticket hint   Count     Percent 
-------------------------+---------+--------
1                         4         0.0008   
1 only                    4         0.0008   
2                         2         0.0004   
2 only                    2         0.0004   
5                         1         0.0002   
5 only                    1         0.0002   
10                        7         0.0014   
10 only                   7         0.0014   
15                        8         0.0016   
15 only                   8         0.0016   
30                        11        0.0021   
30 only                   10        0.0019   
60                        93        0.0181   
60 only                   87        0.0169   
65                        1         0.0002   
65 only                   1         0.0002   
70                        7         0.0014   
100                       14        0.0027   
100 only                  14        0.0027   
120                       30        0.0058   
120 only                  30        0.0058   
128                       2         0.0004   
128 only                  2         0.0004   
150                       2         0.0004   
180                       39        0.0076   
180 only                  37        0.0072   
240                       14        0.0027   
240 only                  14        0.0027   
300                       232702    45.2296  
300 only                  227970    44.3098  
302                       2         0.0004   
302 only                  2         0.0004   
360                       2         0.0004   
360 only                  1         0.0002   
400                       7         0.0014   
400 only                  7         0.0014   
420                       113       0.022    
420 only                  87        0.0169   
480                       11        0.0021   
480 only                  11        0.0021   
500                       4         0.0008   
500 only                  4         0.0008   
540                       1         0.0002   
540 only                  1         0.0002   
600                       24187     4.7012   
600 only                  24031     4.6708   
720                       2         0.0004   
720 only                  2         0.0004   
840                       2         0.0004   
840 only                  2         0.0004   
900                       718       0.1396   
900 only                  702       0.1364   
960                       3         0.0006   
960 only                  3         0.0006   
1200                      2085      0.4053   
1200 only                 2080      0.4043   
1320                      1         0.0002   
1320 only                 1         0.0002   
1500                      11        0.0021   
1500 only                 10        0.0019   
1800                      473       0.0919   
1800 only                 468       0.091    
2100                      1         0.0002   
2100 only                 1         0.0002   
2400                      6         0.0012   
2400 only                 6         0.0012   
2700                      7         0.0014   
2700 only                 7         0.0014   
3000                      19        0.0037   
3000 only                 19        0.0037   
3600                      512       0.0995   
3600 only                 498       0.0968   
3900                      1         0.0002   
3900 only                 1         0.0002   
4200                      1         0.0002   
5160                      1         0.0002   
5160 only                 1         0.0002   
5400                      14        0.0027   
5400 only                 6         0.0012   
6000                      3         0.0006   
6000 only                 3         0.0006   
7200                      16177     3.1443   
7200 only                 16154     3.1398   
10800                     2416      0.4696   
10800 only                2411      0.4686   
14400                     70        0.0136   
14400 only                70        0.0136   
18000                     7         0.0014   
18000 only                7         0.0014   
21600                     4966      0.9652   
21600 only                4963      0.9646   
28800                     2049      0.3983   
28800 only                637       0.1238   
36000                     1187      0.2307   
36000 only                1176      0.2286   
43200                     35        0.0068   
43200 only                35        0.0068   
60000                     1         0.0002   
60000 only                1         0.0002   
64800                     51944     10.0962  
64800 only                51911     10.0898  
72000                     13        0.0025   
72000 only                13        0.0025   
86000                     31        0.006    
86000 only                31        0.006    
86400                     3546      0.6892   
86400 only                3543      0.6886   
100800                    11273     2.1911   
100800 only               11263     2.1892   
129600                    9         0.0017   
129600 only               9         0.0017   
172800                    7         0.0014   
172800 only               7         0.0014   
216000                    1         0.0002   
216000 only               1         0.0002   
432000                    2         0.0004   
432000 only               2         0.0004   
604800                    1         0.0002   
604800 only               1         0.0002   
864000                    3         0.0006   
864000 only               3         0.0006   
2592000                   1         0.0002   
2592000 only              1         0.0002   
None                      166108    32.2859  
None only                 159631    31.027   

Certificate sig alg     Count     Percent 
-------------------------+---------+--------
None                      13099     2.546    
ecdsa-with-SHA256         36858     7.164    
sha1WithRSAEncryption     100797    19.5916  
sha256WithRSAEncryption   377291    73.3329  
sha384WithRSAEncryption   6         0.0012   
sha512WithRSAEncryption   26        0.0051   

Certificate key size    Count     Percent 
-------------------------+---------+--------
ECDSA 256                 36891     7.1704   
ECDSA 384                 8         0.0016   
RSA 1024                  68        0.0132   
RSA 10240                 5         0.001    
RSA 2048                  459006    89.2156  
RSA 2049                  3         0.0006   
RSA 2056                  2         0.0004   
RSA 2058                  2         0.0004   
RSA 2064                  1         0.0002   
RSA 2078                  1         0.0002   
RSA 2080                  2         0.0004   
RSA 2084                  6         0.0012   
RSA 2096                  2         0.0004   
RSA 2408                  1         0.0002   
RSA 2432                  2         0.0004   
RSA 2480                  1         0.0002   
RSA 2890                  1         0.0002   
RSA 3024                  1         0.0002   
RSA 3071                  1         0.0002   
RSA 3072                  119       0.0231   
RSA 3248                  3         0.0006   
RSA 4042                  1         0.0002   
RSA 4048                  1         0.0002   
RSA 4056                  26        0.0051   
RSA 4069                  2         0.0004   
RSA 4092                  6         0.0012   
RSA 4094                  1         0.0002   
RSA 4096                  18374     3.5713   
RSA 8192                  5         0.001    
RSA/ECDSA Dual Stack      44        0.0086

OCSP stapling             Count     Percent 
-------------------------+---------+--------
Supported                 110108    21.4013  
Unsupported               404383    78.5987  

Supported Protocols       Count     Percent
-------------------------+---------+-------
SSL2                      25202     4.8984
SSL2 Only                 15        0.0029
SSL3                      126817    24.649
SSL3 Only                 549       0.1067
SSL3 or TLS1 Only         72846     14.1588
SSL3 or lower Only        571       0.111
TLS1                      510753    99.2735
TLS1 Only                 43061     8.3696
TLS1 or lower Only        96394     18.7358
TLS1.1                    405071    78.7324
TLS1.1 Only               30        0.0058
TLS1.1 or up Only         2939      0.5712
TLS1.2                    415131    80.6877
TLS1.2 Only               1267      0.2463
TLS1.2, 1.0 but not 1.1   11078     2.1532

Statistics from 481615 chains provided by 696385 hosts

Server provided chains    Count     Percent
-------------------------+---------+-------
complete                  438491    62.9667
incomplete                20877     2.9979
untrusted                 237017    34.0353

Trusted chain statistics
========================

Chain length              Count     Percent
-------------------------+---------+-------
2                         214       0.0444
3                         479299    99.5191
4                         2064      0.4286
5                         38        0.0079

CA key size in chains     Count
-------------------------+---------
ECDSA 256                 21571     
ECDSA 384                 21574     
RSA 1024                  189       
RSA 2045                  3         
RSA 2048                  797792    
RSA 4096                  124027    

Chains with CA key        Count     Percent
-------------------------+---------+-------
ECDSA 256                 21571     4.4789
ECDSA 384                 21574     4.4795
RSA 1024                  187       0.0388
RSA 2045                  3         0.0006
RSA 2048                  459556    95.4198
RSA 4096                  123505    25.6439

Signature algorithm (ex. root) Count
------------------------------+---------
ecdsa-with-SHA384              21569     
sha1WithRSAEncryption          87272     
sha256WithRSAEncryption        264799    
sha384WithRSAEncryption        109831    
sha512WithRSAEncryption        70        

Eff. host cert chain LoS  Count     Percent
-------------------------+---------+-------
80                        87432     18.1539
112                       372602    77.3651
128                       21581     4.481

Root CAs                                      Count     Percent
---------------------------------------------+---------+-------
(2c543cd1) GeoTrust Global CA                 102403    21.2624
(d6325660) COMODO RSA Certification Authority 101866    21.1509
(cbf06781) Go Daddy Root Certificate Authorit 47350     9.8315
(5ad8a5d6) GlobalSign Root CA                 41408     8.5977
(b204d74a) VeriSign Class 3 Public Primary Ce 26837     5.5723
(244b5494) DigiCert High Assurance EV Root CA 25125     5.2168
(2e4eed3c) thawte Primary Root CA             22902     4.7553
(eed8c118) COMODO ECC Certification Authority 21557     4.476
(653b494a) Baltimore CyberTrust Root          11908     2.4725
(157753a5) AddTrust External CA Root          10009     2.0782
(ae8153b9) StartCom Certification Authority   8637      1.7933
(fc5a8f99) USERTrust RSA Certification Author 7875      1.6351
(3513523f) DigiCert Global Root CA            7502      1.5577
(4bfab552) Starfield Root Certificate Authori 6246      1.2969
(480720ec) GeoTrust Primary Certification Aut 5252      1.0905
(f387163d) Starfield Technologies, Inc.       4889      1.0151


Scan performed between 18th and 28th of September 2015.

August 2015 scan results

Another rather uneventful month – more TLS servers among Alexa top 1 million, more support for AES-GCM, ECDHE, TLS1.2. Less servers with bad configurations – RC4 and other insecure ciphers, SSL2 and SSL3, SHA-1 certificates.

Cipher suites

AES in CBC mode remains unchanged but we see continued growth of the GCM, with it gaining another 2%. Despite its age, 3DES is still showing growth with 1% more servers supporting it, likely because of removal of RC4, which lost another 3% overall and 0.4% for servers which prefer it. There are still over 1300 servers among Alexa top 1 million that support only RC4 (0.27% of total).

Similarly, the overall percentage of servers which support completely insecure ciphers has dropped by over 1.5%.

Despite FREAK and Logjam, over 6.5% of servers support export grade ciphers.

Key exchange

ECDHE support is still growing, although at a rather slow pace – this month 2.2% more servers were willing to use this mechanism. DHE has fallen by nearly 1.5%

As always, the growth was fuelled by adding support for the P-256 curve.

Support as well as preference for PFS has grown – by just under a 1% and 1.5% respectively

Hash and signature algorithms

Unfortunately the roll-out of TLS 1.2 also brings with itself additional servers willing to negotiate MD5 signature algorithm on ServerKeyExchange messages, it has grown by 1% month over month.

Support for SHA-256 has grown by 2% so deployment of more capable systems is at least higher.

Vulnerabilities

Support for insecure renegotiation is still at a fairly high level of 4%, falling just by 0.2% since last month.

Compression has fallen by a same amount, reducing the percentage of servers vulnerable to CRIME to 2.1%

Certificates

Certificates using SHA-1 signatures have fallen by just over 6%, getting replaced mostly by RSA certificates signed with SHA-256 with some signed by ECDSA.

2048 bit RSA sees little changes, towering at nearly 90% of all servers.

Protocols

SSLv2 and SSLv3 continue their journey down, at the same slow pace. But we are at a level of just 600 servers in Alexa Top 1 million requiring use of SSLv3 to connect. Over 99% of servers support at least TLSv1.0.

At the same time, we have reached the milestone of “only one in five servers supporting TLSv1.0 as the highest protocol version”. We are shy of just 0.3% to be able to say that 4 in 5 servers support TLSv1.2!

Results

SSL/TLS survey of 509351 websites from Alexa's top 1 million
Stats only from connections that did provide valid certificates
(or anonymous DH from servers that do also have valid certificate installed)


Supported Ciphers         Count     Percent
-------------------------+---------+-------
3DES                      435183    85.4387
3DES Only                 725       0.1423
AES                       500583    98.2786
AES Only                  18647     3.6609
AES-CBC                   500485    98.2594
AES-CBC Only              9344      1.8345
AES-GCM                   363787    71.4217
AES-GCM Only              37        0.0073
CAMELLIA                  225125    44.1984
CAMELLIA Only             3         0.0006
CHACHA20                  63145     12.3971
CHACHA20 Only             2         0.0004
Insecure                  67027     13.1593
RC4                       239979    47.1147
RC4 Only                  1395      0.2739
RC4 Preferred             29355     5.7632
RC4 forced in TLS1.1+     16525     3.2443
x:FF 29 RC4 Only          1696      0.333
x:FF 29 RC4 Preferred     33338     6.5452
x:FF 29 incompatible      107       0.021
x:FF 35 RC4 Only          2022      0.397
x:FF 35 RC4 Preferred     33466     6.5703
x:FF 35 incompatible      112       0.022
y:DHE-RSA-SEED-SHA        85997     16.8836
y:IDEA-CBC-SHA            78567     15.4249
y:SEED-SHA                95725     18.7935
z:ADH-AES128-GCM-SHA256   290       0.0569
z:ADH-AES128-SHA          690       0.1355
z:ADH-AES128-SHA256       194       0.0381
z:ADH-AES256-GCM-SHA384   300       0.0589
z:ADH-AES256-SHA          701       0.1376
z:ADH-AES256-SHA256       196       0.0385
z:ADH-CAMELLIA128-SHA     306       0.0601
z:ADH-CAMELLIA256-SHA     312       0.0613
z:ADH-DES-CBC-SHA         295       0.0579
z:ADH-DES-CBC3-SHA        712       0.1398
z:ADH-RC4-MD5             569       0.1117
z:ADH-SEED-SHA            230       0.0452
z:AECDH-AES128-SHA        13191     2.5898
z:AECDH-AES256-SHA        13214     2.5943
z:AECDH-DES-CBC3-SHA      13149     2.5815
z:AECDH-NULL-SHA          51        0.01
z:AECDH-RC4-SHA           12459     2.4461
z:DES-CBC-MD5             12757     2.5046
z:DES-CBC-SHA             38652     7.5885
z:DES-CBC3-MD5            25783     5.0619
z:ECDHE-RSA-NULL-SHA      60        0.0118
z:EDH-RSA-DES-CBC-SHA     33192     6.5165
z:EXP-ADH-DES-CBC-SHA     214       0.042
z:EXP-ADH-RC4-MD5         213       0.0418
z:EXP-DES-CBC-SHA         17083     3.3539
z:EXP-EDH-RSA-DES-CBC-SHA 13893     2.7276
z:EXP-RC2-CBC-MD5         20743     4.0724
z:EXP-RC4-MD5             21811     4.2821
z:EXP1024-DES-CBC-SHA     5319      1.0443
z:EXP1024-RC4-SHA         5395      1.0592
z:IDEA-CBC-MD5            2435      0.4781
z:NULL-MD5                230       0.0452
z:NULL-SHA                232       0.0455
z:NULL-SHA256             22        0.0043
z:RC2-CBC-MD5             13042     2.5605
z:RC4-64-MD5              1052      0.2065

Cipher ordering           Count     Percent
-------------------------+---------+-------
Client side               130864    25.6923
Server side               378487    74.3077

Supported Handshakes      Count     Percent
-------------------------+---------+-------
ADH                       817       0.1604
AECDH                     13248     2.601
DHE                       280098    54.9912
ECDH                      3         0.0006
ECDHE                     390772    76.7196
ECDHE and DHE             205466    40.3388
RSA                       463146    90.9287

Supported PFS             Count     Percent  PFS Percent
-------------------------+---------+--------+-----------
DH,1024bits               187360    36.7841  66.8909
DH,1536bits               2         0.0004   0.0007
DH,2048bits               83731     16.4388  29.8935
DH,2236bits               3         0.0006   0.0011
DH,3072bits               2656      0.5214   0.9482
DH,3092bits               1         0.0002   0.0004
DH,4096bits               5788      1.1363   2.0664
DH,512bits                59        0.0116   0.0211
DH,768bits                553       0.1086   0.1974
DH,8192bits               2         0.0004   0.0007
ECDH,B-163,163bits        1         0.0002   0.0003
ECDH,B-571,570bits        1431      0.2809   0.3662
ECDH,K-163,163bits        1         0.0002   0.0003
ECDH,K-571,570bits        1         0.0002   0.0003
ECDH,P-224,224bits        83        0.0163   0.0212
ECDH,P-256,256bits        379964    74.5977  97.2342
ECDH,P-384,384bits        2696      0.5293   0.6899
ECDH,P-521,521bits        7641      1.5001   1.9554
Prefer DH,1024bits        70139     13.7703  25.0409
Prefer DH,1536bits        1         0.0002   0.0004
Prefer DH,2048bits        6067      1.1911   2.166
Prefer DH,2236bits        1         0.0002   0.0004
Prefer DH,3072bits        21        0.0041   0.0075
Prefer DH,4096bits        310       0.0609   0.1107
Prefer DH,768bits         170       0.0334   0.0607
Prefer ECDH,B-163,163bits 1         0.0002   0.0003
Prefer ECDH,B-571,570bits 1231      0.2417   0.315
Prefer ECDH,K-163,163bits 1         0.0002   0.0003
Prefer ECDH,K-571,570bits 1         0.0002   0.0003
Prefer ECDH,P-224,224bits 49        0.0096   0.0125
Prefer ECDH,P-256,256bits 327275    64.2533  83.7509
Prefer ECDH,P-384,384bits 2552      0.501    0.6531
Prefer ECDH,P-521,521bits 6909      1.3564   1.768
Prefer PFS                414728    81.4228  0
Support PFS               465404    91.372   0

Supported ECC curves      Count     Percent 
-------------------------+---------+--------
brainpoolP256r1           1013      0.1989   
brainpoolP384r1           1014      0.1991   
brainpoolP512r1           1015      0.1993   
prime192v1                1346      0.2643   
prime256v1                389473    76.4646  
prime256v1 Only           338238    66.4057  
secp160k1                 1313      0.2578   
secp160r1                 1315      0.2582   
secp160r2                 1312      0.2576   
secp192k1                 1335      0.2621   
secp224k1                 1403      0.2754   
secp224r1                 3044      0.5976   
secp224r1 Only            2         0.0004   
secp256k1                 2305      0.4525   
secp384r1                 51317     10.075   
secp384r1 Only            330       0.0648   
secp521r1                 20958     4.1146   
secp521r1 Only            124       0.0243   
sect163k1                 1322      0.2595   
sect163k1 Only            2         0.0004   
sect163r1                 1320      0.2592   
sect163r2                 1319      0.259    
sect163r2 Only            1         0.0002   
sect193r1                 1316      0.2584   
sect193r2                 1315      0.2582   
sect233k1                 1395      0.2739   
sect233r1                 1395      0.2739   
sect239k1                 1394      0.2737   
sect283k1                 2280      0.4476   
sect283r1                 2279      0.4474   
sect409k1                 2281      0.4478   
sect409r1                 2278      0.4472   
sect571k1                 2291      0.4498   
sect571r1                 2290      0.4496   

Unsupported curve fallback     Count     Percent 
------------------------------+---------+--------
False                          76188     14.9579  
True                           263977    51.8261  
order-specific                 263       0.0516   
unknown                        168923    33.1644  

ECC curve ordering        Count     Percent 
-------------------------+---------+--------
client                    3661      0.7188   
inconclusive-noecc        9         0.0018   
server                    386286    75.8389  
unknown                   119395    23.4406  

TLSv1.2 PFS supported sigalgs  Count     Percent 
------------------------------+---------+--------
ECDSA-SHA1                     35626     6.9944   
ECDSA-SHA1 Only                4         0.0008   
ECDSA-SHA224                   35618     6.9928   
ECDSA-SHA256                   35628     6.9948   
ECDSA-SHA384                   35625     6.9942   
ECDSA-SHA512                   35631     6.9954   
ECDSA-SHA512 Only              6         0.0012   
RSA-MD5                        165235    32.4403  
RSA-SHA1                       341873    67.1193  
RSA-SHA1 Only                  46530     9.1352   
RSA-SHA224                     277602    54.5011  
RSA-SHA256                     301111    59.1166  
RSA-SHA256 Only                4859      0.954    
RSA-SHA384                     278555    54.6882  
RSA-SHA512                     278643    54.7055  
RSA-SHA512 Only                93        0.0183   

TLSv1.2 PFS ordering           Count     Percent 
------------------------------+---------+--------
client                         243146    47.7364  
indeterminate                  8         0.0016   
intolerant                     3556      0.6981   
order-fallback                 16        0.0031   
server                         136828    26.8632  
unsupported                    22608     4.4386   

TLSv1.2 PFS sigalg fallback    Count     Percent 
------------------------------+---------+--------
ECDSA SHA1                     35612     6.9916   
ECDSA intolerant               39        0.0077   
RSA False                      163780    32.1546  
RSA SHA1                       152230    29.8871  
RSA intolerant                 30949     6.0762   
RSA soft-nopfs                 1543      0.3029   

Renegotiation             Count     Percent 
-------------------------+---------+--------
False                     6729      1.3211   
insecure                  20615     4.0473   
secure                    482007    94.6316  

Compression               Count     Percent 
-------------------------+---------+--------
1 (zlib compression)      10877     2.1355   
False                     6729      1.3211   
NONE                      491745    96.5434  

TLS session ticket hint   Count     Percent 
-------------------------+---------+--------
1                         2         0.0004   
1 only                    2         0.0004   
2                         2         0.0004   
2 only                    2         0.0004   
5                         4         0.0008   
5 only                    4         0.0008   
10                        7         0.0014   
10 only                   7         0.0014   
15                        10        0.002    
15 only                   10        0.002    
30                        10        0.002    
30 only                   9         0.0018   
60                        100       0.0196   
60 only                   92        0.0181   
65                        1         0.0002   
65 only                   1         0.0002   
70                        6         0.0012   
100                       12        0.0024   
100 only                  12        0.0024   
120                       32        0.0063   
120 only                  32        0.0063   
128                       3         0.0006   
128 only                  3         0.0006   
150                       2         0.0004   
180                       52        0.0102   
180 only                  50        0.0098   
240                       14        0.0027   
240 only                  14        0.0027   
300                       227236    44.6129  
300 only                  222350    43.6536  
302                       1         0.0002   
302 only                  1         0.0002   
360                       3         0.0006   
360 only                  1         0.0002   
400                       7         0.0014   
400 only                  7         0.0014   
420                       113       0.0222   
420 only                  82        0.0161   
450                       1         0.0002   
450 only                  1         0.0002   
480                       12        0.0024   
480 only                  12        0.0024   
500                       4         0.0008   
500 only                  4         0.0008   
540                       1         0.0002   
540 only                  1         0.0002   
600                       23677     4.6485   
600 only                  23483     4.6104   
720                       1         0.0002   
720 only                  1         0.0002   
840                       2         0.0004   
840 only                  2         0.0004   
900                       664       0.1304   
900 only                  648       0.1272   
960                       2         0.0004   
960 only                  2         0.0004   
1200                      1996      0.3919   
1200 only                 1989      0.3905   
1500                      8         0.0016   
1500 only                 7         0.0014   
1800                      449       0.0882   
1800 only                 441       0.0866   
2400                      6         0.0012   
2400 only                 6         0.0012   
2700                      6         0.0012   
2700 only                 6         0.0012   
3000                      20        0.0039   
3000 only                 20        0.0039   
3600                      463       0.0909   
3600 only                 439       0.0862   
3900                      1         0.0002   
3900 only                 1         0.0002   
5400                      15        0.0029   
5400 only                 5         0.001    
6000                      6         0.0012   
6000 only                 6         0.0012   
7200                      15785     3.099    
7200 only                 15761     3.0943   
10800                     2395      0.4702   
10800 only                2391      0.4694   
14400                     73        0.0143   
14400 only                73        0.0143   
18000                     14        0.0027   
18000 only                14        0.0027   
21600                     5069      0.9952   
21600 only                5067      0.9948   
28800                     1936      0.3801   
28800 only                846       0.1661   
36000                     1219      0.2393   
36000 only                1212      0.2379   
43200                     32        0.0063   
43200 only                32        0.0063   
60000                     1         0.0002   
60000 only                1         0.0002   
64800                     50264     9.8682   
64800 only                50206     9.8569   
72000                     10        0.002    
72000 only                10        0.002    
84600                     1         0.0002   
84600 only                1         0.0002   
86000                     37        0.0073   
86000 only                37        0.0073   
86400                     3516      0.6903   
86400 only                3515      0.6901   
100800                    12467     2.4476   
100800 only               12460     2.4463   
115200                    1         0.0002   
115200 only               1         0.0002   
129600                    7         0.0014   
129600 only               7         0.0014   
172800                    8         0.0016   
172800 only               8         0.0016   
216000                    1         0.0002   
216000 only               1         0.0002   
432000                    2         0.0004   
432000 only               2         0.0004   
604800                    1         0.0002   
864000                    2         0.0004   
864000 only               2         0.0004   
2592000                   1         0.0002   
2592000 only              1         0.0002   
None                      167946    32.9725  
None only                 161562    31.7192  

Certificate sig alg     Count     Percent 
-------------------------+---------+--------
None                      13903     2.7296   
ecdsa-with-SHA256         35609     6.9911   
sha1WithRSAEncryption     118117    23.1897  
sha256WithRSAEncryption   355741    69.842   
sha384WithRSAEncryption   5         0.001    
sha512WithRSAEncryption   17        0.0033   

Certificate key size    Count     Percent 
-------------------------+---------+--------
ECDSA 256                 35649     6.9989   
ECDSA 384                 6         0.0012   
ECDSA 521                 1         0.0002   
RSA 1024                  81        0.0159   
RSA 10240                 7         0.0014   
RSA 2048                  455461    89.4199  
RSA 2049                  3         0.0006   
RSA 2056                  2         0.0004   
RSA 2058                  2         0.0004   
RSA 2064                  1         0.0002   
RSA 2080                  2         0.0004   
RSA 2084                  5         0.001    
RSA 2408                  1         0.0002   
RSA 2432                  2         0.0004   
RSA 2480                  1         0.0002   
RSA 2890                  1         0.0002   
RSA 3071                  2         0.0004   
RSA 3072                  111       0.0218   
RSA 3102                  1         0.0002   
RSA 3248                  3         0.0006   
RSA 4042                  1         0.0002   
RSA 4048                  1         0.0002   
RSA 4056                  25        0.0049   
RSA 4069                  3         0.0006   
RSA 4086                  2         0.0004   
RSA 4092                  6         0.0012   
RSA 4094                  1         0.0002   
RSA 4096                  18024     3.5386   
RSA 8192                  5         0.001    
RSA/ECDSA Dual Stack      50        0.0098

OCSP stapling             Count     Percent 
-------------------------+---------+--------
Supported                 109199    21.4389  
Unsupported               400152    78.5611  

Supported Protocols       Count     Percent
-------------------------+---------+-------
SSL2                      26076     5.1195
SSL2 Only                 24        0.0047
SSL3                      130306    25.5828
SSL3 Only                 584       0.1147
SSL3 or TLS1 Only         75720     14.866
SSL3 or lower Only        607       0.1192
TLS1                      506048    99.3515
TLS1 Only                 44327     8.7026
TLS1 or lower Only        100132    19.6587
TLS1.1                    396444    77.8332
TLS1.1 Only               30        0.0059
TLS1.1 or up Only         2473      0.4855
TLS1.2                    406149    79.7385
TLS1.2 Only               1063      0.2087
TLS1.2, 1.0 but not 1.1   11004     2.1604

Statistics from 528021 chains provided by 691201 hosts

Server provided chains    Count     Percent
-------------------------+---------+-------
complete                  479672    69.3969
incomplete                23576     3.4109
untrusted                 187953    27.1922

Trusted chain statistics
========================

Chain length              Count     Percent
-------------------------+---------+-------
2                         269       0.0509
3                         525613    99.544
4                         2106      0.3988
5                         33        0.0062

CA key size in chains     Count
-------------------------+---------
ECDSA 256                 35610     
ECDSA 384                 35613     
RSA 1024                  255       
RSA 2045                  1         
RSA 2048                  860646    
RSA 4096                  125820    

Chains with CA key        Count     Percent
-------------------------+---------+-------
ECDSA 256                 35610     6.744
ECDSA 384                 35613     6.7446
RSA 1024                  253       0.0479
RSA 2045                  1         0.0002
RSA 2048                  491885    93.1563
RSA 4096                  125302    23.7305

Signature algorithm (ex. root) Count
------------------------------+---------
ecdsa-with-SHA384              35609     
sha1WithRSAEncryption          136788    
sha256WithRSAEncryption        246213    
sha384WithRSAEncryption        111253    
sha512WithRSAEncryption        61        

Eff. host cert chain LoS  Count     Percent
-------------------------+---------+-------
80                        137062    25.9577
112                       355341    67.2968
128                       35618     6.7456

Root CAs                                      Count     Percent
---------------------------------------------+---------+-------
(2c543cd1) GeoTrust Global CA                 109891    20.8119
(d6325660) COMODO RSA Certification Authority 103786    19.6557
(5ad8a5d6) GlobalSign Root CA                 51859     9.8214
(cbf06781) Go Daddy Root Certificate Authorit 48094     9.1083
(eed8c118) COMODO ECC Certification Authority 35597     6.7416
(b204d74a) VeriSign Class 3 Public Primary Ce 30261     5.731
(244b5494) DigiCert High Assurance EV Root CA 26028     4.9293
(2e4eed3c) thawte Primary Root CA             24484     4.6369
(157753a5) AddTrust External CA Root          12314     2.3321
(653b494a) Baltimore CyberTrust Root          12080     2.2878
(ae8153b9) StartCom Certification Authority   9217      1.7456
(3513523f) DigiCert Global Root CA            7329      1.388
(fc5a8f99) USERTrust RSA Certification Author 7360      1.3939
(4bfab552) Starfield Root Certificate Authori 6079      1.1513
(f081611a) The Go Daddy Group, Inc.           5382      1.0193
(480720ec) GeoTrust Primary Certification Aut 5448      1.0318
(f387163d) Starfield Technologies, Inc.       5310      1.0056


Scan performed between 17th of August and 4th of September 2015.

February 2015 scan results

This month the amount of HTTP servers with trusted certificate has grown again,
this time by just under 2%.

Cipher suites that use 3DES or AES have essentially retained their marketshare,
with slight increase in 3DES and AES-GCM use. Servers which support just RC4 or
prefer RC4 over other ciphers has also remained unchanged, as have the use of
completely insecure export grade and 54 bit ciphers.

Server side cipher ordering also didn’t change by much, though it has risen.

Support for ciphersuites that provides forward secrecy has also seen only
insignificant changes. Preference for DHE has remained the same, for ECDHE
has risen only very slightly. Though it is a bit surprising, as support for both
ECDHE and DHE has risen by more than a percent. Nearly all of this change is
attributed to support for P-256 curve and 2048 bit finite-field DHE.

Similarly, support for server side curve ordering or chosen signature algorithms
essentially remained the same.

The only measurement that has noted change above 1% are the signature algorithms
on server certificates, with SHA-1 loosing another 3.8% and SHA-256 gaining same
amount. Used key sizes haven’t changed though.

SSLv3 support still remains high, with 33% of surveyed servers still supporting
this insecure protocol. The good news is that only 0.33% of all servers scanned
support just SSLv3 or SSLv2, so browsers and users are safe to disable this
protocol without fear of interoperability issues.

SSL/TLS survey of 478847 websites from Alexa's top 1 million
Stats only from connections that did provide valid certificates
(or anonymous DH from servers that do also have valid certificate installed)


Supported Ciphers         Count     Percent
-------------------------+---------+-------
3DES                      389395    81.3193
3DES Only                 446       0.0931
AES                       452703    94.5402
AES Only                  7959      1.6621
AES-CBC Only              4111      0.8585
AES-GCM                   275395    57.5121
AES-GCM Only              21        0.0044
CAMELLIA                  201517    42.0838
CAMELLIA Only             1         0.0002
CHACHA20                  27231     5.6868
Insecure                  88014     18.3804
RC4                       362499    75.7025
RC4 Only                  3578      0.7472
RC4 Preferred             63514     13.2639
RC4 forced in TLS1.1+     40750     8.51
x:FF 29 RC4 Only          545       0.1138
x:FF 29 RC4 Preferred     68531     14.3117
x:FF 29 incompatible      135       0.0282
y:DHE-RSA-SEED-SHA        106333    22.206
y:IDEA-CBC-MD5            2911      0.6079
y:IDEA-CBC-SHA            85651     17.8869
y:SEED-SHA                103273    21.567
z:ADH-AES128-GCM-SHA256   352       0.0735
z:ADH-AES128-SHA          983       0.2053
z:ADH-AES128-SHA256       278       0.0581
z:ADH-AES256-GCM-SHA384   367       0.0766
z:ADH-AES256-SHA          995       0.2078
z:ADH-AES256-SHA256       282       0.0589
z:ADH-CAMELLIA128-SHA     440       0.0919
z:ADH-CAMELLIA256-SHA     449       0.0938
z:ADH-DES-CBC-SHA         378       0.0789
z:ADH-DES-CBC3-SHA        1011      0.2111
z:ADH-RC4-MD5             787       0.1644
z:ADH-SEED-SHA            293       0.0612
z:AECDH-AES128-SHA        14530     3.0344
z:AECDH-AES256-SHA        14530     3.0344
z:AECDH-DES-CBC3-SHA      14487     3.0254
z:AECDH-NULL-SHA          38        0.0079
z:AECDH-RC4-SHA           13507     2.8207
z:DES-CBC-MD5             18469     3.857
z:DES-CBC-SHA             49506     10.3386
z:DES-CBC3-MD5            33718     7.0415
z:ECDHE-RSA-NULL-SHA      43        0.009
z:EDH-RSA-DES-CBC-SHA     42281     8.8298
z:EXP-ADH-DES-CBC-SHA     302       0.0631
z:EXP-ADH-RC4-MD5         306       0.0639
z:EXP-DES-CBC-SHA         35244     7.3602
z:EXP-EDH-RSA-DES-CBC-SHA 24614     5.1403
z:EXP-RC2-CBC-MD5         40047     8.3632
z:EXP-RC4-MD5             42873     8.9534
z:EXP1024-DES-CBC-SHA     9396      1.9622
z:EXP1024-RC4-SHA         9557      1.9958
z:NULL-MD5                292       0.061
z:NULL-SHA                292       0.061
z:NULL-SHA256             12        0.0025
z:RC2-CBC-MD5             18829     3.9322
z:RC4-64-MD5              1529      0.3193

Cipher ordering           Count     Percent
-------------------------+---------+-------
Client side               141265    29.5011
Server side               337582    70.4989

Supported Handshakes      Count     Percent
-------------------------+---------+-------
ADH                       1120      0.2339
AECDH                     14557     3.04
DHE                       256190    53.5014
ECDHE                     305994    63.9022
ECDHE and DHE             154553    32.2761
RSA                       446580    93.2615

Supported PFS             Count     Percent  PFS Percent
-------------------------+---------+--------+-----------
DH,1024bits               214103    44.7122  83.572
DH,1536bits               1         0.0002   0.0004
DH,2048bits               39131     8.1719   15.2742
DH,2226bits               1         0.0002   0.0004
DH,2236bits               1         0.0002   0.0004
DH,3072bits               19        0.004    0.0074
DH,3248bits               2         0.0004   0.0008
DH,4094bits               1         0.0002   0.0004
DH,4096bits               2115      0.4417   0.8256
DH,512bits                87        0.0182   0.034
DH,768bits                759       0.1585   0.2963
DH,8192bits               1         0.0002   0.0004
ECDH,B-163,163bits        7         0.0015   0.0023
ECDH,B-571,570bits        707       0.1476   0.2311
ECDH,K-163,163bits        1         0.0002   0.0003
ECDH,P-224,224bits        51        0.0107   0.0167
ECDH,P-256,256bits        299807    62.6102  97.9781
ECDH,P-384,384bits        3156      0.6591   1.0314
ECDH,P-521,521bits        4454      0.9302   1.4556
Prefer DH,1024bits        99375     20.753   38.7896
Prefer DH,2048bits        2882      0.6019   1.1249
Prefer DH,2236bits        1         0.0002   0.0004
Prefer DH,4096bits        90        0.0188   0.0351
Prefer DH,512bits         3         0.0006   0.0012
Prefer DH,768bits         420       0.0877   0.1639
Prefer ECDH,B-163,163bits 7         0.0015   0.0023
Prefer ECDH,B-571,570bits 521       0.1088   0.1703
Prefer ECDH,K-163,163bits 1         0.0002   0.0003
Prefer ECDH,P-224,224bits 18        0.0038   0.0059
Prefer ECDH,P-256,256bits 243201    50.7889  79.479
Prefer ECDH,P-384,384bits 3079      0.643    1.0062
Prefer ECDH,P-521,521bits 4146      0.8658   1.3549
Prefer PFS                353744    73.8741  0
Support PFS               407631    85.1276  0

Supported ECC curves      Count     Percent 
-------------------------+---------+--------
brainpoolP256r1           77        0.0161   
brainpoolP384r1           77        0.0161   
brainpoolP512r1           77        0.0161   
prime192v1                721       0.1506   
prime256v1                305466    63.792   
prime256v1 Only           265378    55.4202  
secp160k1                 689       0.1439   
secp160r1                 688       0.1437   
secp160r2                 688       0.1437   
secp192k1                 716       0.1495   
secp224k1                 747       0.156    
secp224r1                 1221      0.255    
secp224r1 Only            1         0.0002   
secp256k1                 766       0.16     
secp384r1                 40252     8.406    
secp384r1 Only            166       0.0347   
secp521r1                 9985      2.0852   
secp521r1 Only            86        0.018    
sect163k1                 688       0.1437   
sect163r1                 688       0.1437   
sect163r2                 695       0.1451   
sect163r2 Only            7         0.0015   
sect193r1                 688       0.1437   
sect193r2                 688       0.1437   
sect233k1                 738       0.1541   
sect233r1                 738       0.1541   
sect239k1                 737       0.1539   
sect283k1                 737       0.1539   
sect283r1                 737       0.1539   
sect409k1                 737       0.1539   
sect409r1                 737       0.1539   
sect571k1                 756       0.1579   
sect571r1                 756       0.1579   

Unsupported curve fallback     Count     Percent 
------------------------------+---------+--------
False                          75947     15.8604  
True                           188432    39.3512  
order-specific                 12        0.0025   
unknown                        214456    44.7859  

ECC curve ordering        Count     Percent 
-------------------------+---------+--------
client                    1661      0.3469   
inconclusive-noecc        4         0.0008   
server                    304074    63.5013  
unknown                   173108    36.151   

TLSv1.2 PFS supported sigalgs  Count     Percent 
------------------------------+---------+--------
ECDSA-SHA1                     27872     5.8206   
ECDSA-SHA224                   27873     5.8209   
ECDSA-SHA256                   27873     5.8209   
ECDSA-SHA384                   27874     5.8211   
ECDSA-SHA512                   27874     5.8211   
RSA-MD5                        132832    27.74    
RSA-MD5 Only                   1         0.0002   
RSA-SHA1                       275469    57.5276  
RSA-SHA1 Only                  42560     8.888    
RSA-SHA224                     224806    46.9474  
RSA-SHA256                     235988    49.2825  
RSA-SHA256 Only                2701      0.5641   
RSA-SHA384                     225210    47.0317  
RSA-SHA512                     225254    47.0409  
RSA-SHA512 Only                39        0.0081   

TLSv1.2 PFS ordering           Count     Percent 
------------------------------+---------+--------
client                         206251    43.0724  
indeterminate                  7         0.0015   
intolerant                     1409      0.2942   
order-fallback                 2         0.0004   
server                         98943     20.6628  
unsupported                    37273     7.7839   

TLSv1.2 PFS sigalg fallback    Count     Percent 
------------------------------+---------+--------
ECDSA SHA1                     27871     5.8204   
ECDSA intolerant               4         0.0008   
ECDSA pfs-rsa-SHA512           1         0.0002   
RSA False                      131264    27.4125  
RSA SHA1                       125024    26.1094  
RSA intolerant                 20874     4.3592   
RSA pfs-ecdsa-SHA512           1         0.0002   
RSA soft-nopfs                 1609      0.336    

Renegotiation             Count     Percent 
-------------------------+---------+--------
False                     9764      2.0391   
insecure                  25819     5.3919   
secure                    443264    92.569   

Compression               Count     Percent 
-------------------------+---------+--------
1 (zlib compression)      15459     3.2284   
False                     9764      2.0391   
NONE                      453624    94.7326  

TLS session ticket hint   Count     Percent 
-------------------------+---------+--------
1                         2         0.0004   
1 only                    2         0.0004   
2                         2         0.0004   
2 only                    2         0.0004   
5                         1         0.0002   
5 only                    1         0.0002   
10                        4         0.0008   
10 only                   4         0.0008   
15                        8         0.0017   
15 only                   8         0.0017   
30                        10        0.0021   
30 only                   10        0.0021   
60                        71        0.0148   
60 only                   64        0.0134   
65                        1         0.0002   
65 only                   1         0.0002   
70                        4         0.0008   
75                        1         0.0002   
75 only                   1         0.0002   
100                       11        0.0023   
100 only                  11        0.0023   
120                       24        0.005    
120 only                  23        0.0048   
128                       3         0.0006   
128 only                  3         0.0006   
180                       47        0.0098   
180 only                  45        0.0094   
240                       11        0.0023   
240 only                  11        0.0023   
300                       201017    41.9794  
300 only                  192323    40.1638  
360                       2         0.0004   
360 only                  1         0.0002   
400                       4         0.0008   
400 only                  4         0.0008   
420                       37        0.0077   
420 only                  26        0.0054   
480                       16        0.0033   
480 only                  14        0.0029   
500                       4         0.0008   
500 only                  4         0.0008   
600                       14965     3.1252   
600 only                  14676     3.0649   
720                       1         0.0002   
720 only                  1         0.0002   
840                       1         0.0002   
840 only                  1         0.0002   
900                       520       0.1086   
900 only                  500       0.1044   
960                       2         0.0004   
960 only                  2         0.0004   
1000                      1         0.0002   
1000 only                 1         0.0002   
1200                      286       0.0597   
1200 only                 283       0.0591   
1500                      9         0.0019   
1500 only                 8         0.0017   
1800                      343       0.0716   
1800 only                 334       0.0698   
2100                      1         0.0002   
2100 only                 1         0.0002   
2400                      2         0.0004   
2400 only                 2         0.0004   
2700                      5         0.001    
2700 only                 5         0.001    
3000                      11        0.0023   
3000 only                 11        0.0023   
3600                      329       0.0687   
3600 only                 312       0.0652   
5400                      10        0.0021   
6000                      3         0.0006   
6000 only                 3         0.0006   
7200                      14085     2.9414   
7200 only                 11423     2.3855   
10800                     1006      0.2101   
10800 only                1001      0.209    
14400                     1416      0.2957   
14400 only                1415      0.2955   
18000                     1         0.0002   
18000 only                1         0.0002   
21600                     4976      1.0392   
21600 only                4973      1.0385   
28800                     12        0.0025   
28800 only                11        0.0023   
36000                     980       0.2047   
36000 only                975       0.2036   
43200                     101       0.0211   
43200 only                101       0.0211   
60000                     1         0.0002   
60000 only                1         0.0002   
64800                     45713     9.5465   
64800 only                45710     9.5458   
72000                     8         0.0017   
72000 only                8         0.0017   
86000                     28        0.0058   
86000 only                28        0.0058   
86400                     225       0.047    
86400 only                224       0.0468   
93600                     1         0.0002   
93600 only                1         0.0002   
100800                    12805     2.6741   
100800 only               12805     2.6741   
129600                    8         0.0017   
129600 only               8         0.0017   
172800                    1         0.0002   
172800 only               1         0.0002   
604800                    1         0.0002   
604800 only               1         0.0002   
864000                    3         0.0006   
864000 only               3         0.0006   
None                      191458    39.9831  
None only                 179709    37.5295  

Certificate sig alg     Count     Percent 
-------------------------+---------+--------
None                      15481     3.233    
ecdsa-with-SHA256         27852     5.8165   
sha1WithRSAEncryption     247414    51.6687  
sha256WithRSAEncryption   203665    42.5324  
sha512WithRSAEncryption   10        0.0021   

Certificate key size    Count     Percent 
-------------------------+---------+--------
ECDSA 256                 27873     5.8209   
ECDSA 384                 4         0.0008   
RSA 1024                  586       0.1224   
RSA 10240                 4         0.0008   
RSA 2028                  1         0.0002   
RSA 2047                  1         0.0002   
RSA 2048                  434653    90.7707  
RSA 2049                  2         0.0004   
RSA 2056                  3         0.0006   
RSA 2058                  4         0.0008   
RSA 2064                  1         0.0002   
RSA 2080                  2         0.0004   
RSA 2084                  14        0.0029   
RSA 2096                  1         0.0002   
RSA 2408                  3         0.0006   
RSA 2432                  5         0.001    
RSA 2612                  1         0.0002   
RSA 3072                  81        0.0169   
RSA 3102                  1         0.0002   
RSA 3248                  3         0.0006   
RSA 3600                  1         0.0002   
RSA 4042                  1         0.0002   
RSA 4048                  2         0.0004   
RSA 4056                  32        0.0067   
RSA 4069                  1         0.0002   
RSA 4086                  2         0.0004   
RSA 4092                  2         0.0004   
RSA 4096                  15597     3.2572   
RSA 4098                  2         0.0004   
RSA 8192                  4         0.0008   
RSA/ECDSA Dual Stack      30        0.0063

OCSP stapling             Count     Percent 
-------------------------+---------+--------
Supported                 79626     16.6287  
Unsupported               399221    83.3713  

Supported Protocols       Count     Percent
-------------------------+---------+-------
SSL2                      34004     7.1012
SSL2 Only                 83        0.0173
SSL3                      160049    33.4238
SSL3 Only                 1554      0.3245
SSL3 or TLS1 Only         99562     20.792
SSL3 or lower Only        1597      0.3335
TLS1                      476217    99.4508
TLS1 Only                 53875     11.251
TLS1 or lower Only        130773    27.31
TLS1.1                    333272    69.5988
TLS1.1 Only               6         0.0013
TLS1.1 or up Only         690       0.1441
TLS1.2                    343871    71.8123
TLS1.2 Only               495       0.1034
TLS1.2, 1.0 but not 1.1   12594     2.6301

Statistics from 506677 chains provided by 663743 hosts

Server provided chains    Count     Percent
-------------------------+---------+-------
complete                  445855    67.1728
incomplete                28915     4.3564
untrusted                 188973    28.4708


Trusted chain statistics
========================

Chain length              Count     Percent
-------------------------+---------+-------
2                         1250      0.2467
3                         435699    85.9915
4                         69697     13.7557
5                         31        0.0061

CA key size in chains     Count
-------------------------+---------
ECDSA 256                 27724     
ECDSA 384                 27724     
RSA 1024                  1237      
RSA 2045                  1         
RSA 2048                  945864    
RSA 4096                  79313     

Chains with CA key        Count     Percent
-------------------------+---------+-------
ECDSA 256                 27724     5.4717
ECDSA 384                 27724     5.4717
RSA 1024                  1233      0.2434
RSA 2045                  1         0.0002
RSA 2048                  477582    94.2577
RSA 4096                  78697     15.532

Signature algorithm (ex. root) Count
------------------------------+---------
ecdsa-with-SHA384              27724     
sha1WithRSAEncryption          272982    
sha256WithRSAEncryption        141436    
sha384WithRSAEncryption        133014    
sha512WithRSAEncryption        30        

Eff. host cert chain LoS  Count     Percent
-------------------------+---------+-------
80                        273108    53.9018
112                       205843    40.6261
128                       27726     5.4721

Root CAs                                      Count     Percent
---------------------------------------------+---------+-------
(2c543cd1) GeoTrust Global CA                 112003    22.1054
(157753a5) AddTrust External CA Root          103054    20.3392
(5ad8a5d6) GlobalSign Root CA                 51402     10.1449
(cbf06781) Go Daddy Root Certificate Authorit 42982     8.4831
(b204d74a) VeriSign Class 3 Public Primary Ce 29072     5.7378
(eed8c118) COMODO ECC Certification Authority 27720     5.4709
(2e4eed3c) thawte Primary Root CA             26917     5.3125
(244b5494) DigiCert High Assurance EV Root CA 23747     4.6868
(653b494a) Baltimore CyberTrust Root          11804     2.3297
(f081611a) The Go Daddy Group, Inc.           11749     2.3188
(b13cc6df) UTN-USERFirst-Hardware             9836      1.9413
(ae8153b9) StartCom Certification Authority   9546      1.884
(f387163d) Starfield Technologies, Inc.       8019      1.5827
(40547a79) COMODO Certification Authority     6997      1.381
(3513523f) DigiCert Global Root CA            5757      1.1362


Scan performed between 19th and 27th of February 2015.