How to run nmap to validate SSL transmission

nmap --script ssl-cert,ssl-enum-ciphers -p 443 it.i88.ca

Starting Nmap 7.60 ( https://nmap.org ) at 2018-04-12 20:05 UTC
Nmap scan report for it.i88.ca (104.28.28.79)
Host is up (0.0088s latency).
Other addresses for it.i88.ca (not scanned): 104.28.29.79 2400:cb00:2048:1::681c:1c4f 2400:cb00:2048:1::681c:1d4f

PORT    STATE SERVICE
443/tcp open  https
| ssl-cert: Subject: commonName=sni69294.cloudflaressl.com
| Subject Alternative Name: DNS:sni69294.cloudflaressl.com, DNS:*.2cdn.eu, DNS:*.aceitunoarts.com, DNS:*.alexwacker.com, DNS:*.alvarezperea.org, DNS:*.dwnlodit.com, DNS:*.easyhairstylesformediumhair.tk, DNS:*.fbnist.com, DNS:*.getfiles.co, DNS:*.goyun.info, DNS:*.hdgem.com, DNS:*.hhgem.com, DNS:*.hqgem.com, DNS:*.i88.ca, DNS:*.impactshared.net, DNS:*.impactvps.net, DNS:*.licensebyte.com, DNS:*.lnkmeup.com, DNS:*.miguesamana.ml, DNS:*.musiclatinoradio.ml, DNS:*.mycustom.click, DNS:*.octranspo.org, DNS:*.peliculaxd.com, DNS:*.primaria1decembrie.ro, DNS:*.radiopodersatelite.com.pe, DNS:*.registrando.net, DNS:*.rosecure.ro, DNS:*.sharedpanel.com, DNS:*.speedy-files.com, DNS:*.strategiadesecuritate.ro, DNS:*.streamingradio.me, DNS:*.subnetlabs.net, DNS:*.zcontentlocker7gpa8a.xyz, DNS:2cdn.eu, DNS:aceitunoarts.com, DNS:alexwacker.com, DNS:alvarezperea.org, DNS:dwnlodit.com, DNS:easyhairstylesformediumhair.tk, DNS:fbnist.com, DNS:getfiles.co, DNS:goyun.info, DNS:hdgem.com, DNS:hhgem.com, DNS:hqgem.com, DNS:i88.ca, DNS:impactshared.net, DNS:impactvps.net, DNS:licensebyte.com, DNS:lnkmeup.com, DNS:miguesamana.ml, DNS:musiclatinoradio.ml, DNS:mycustom.click, DNS:octranspo.org, DNS:peliculaxd.com, DNS:primaria1decembrie.ro, DNS:radiopodersatelite.com.pe, DNS:registrando.net, DNS:rosecure.ro, DNS:sharedpanel.com, DNS:speedy-files.com, DNS:strategiadesecuritate.ro, DNS:streamingradio.me, DNS:subnetlabs.net, DNS:zcontentlocker7gpa8a.xyz
| Issuer: commonName=COMODO ECC Domain Validation Secure Server CA 2/organizationName=COMODO CA Limited/stateOrProvinceName=Greater Manchester/countryName=GB
| Public Key type: ec
| Public Key bits: 256
| Signature Algorithm: ecdsa-with-SHA256
| Not valid before: 2018-04-11T00:00:00
| Not valid after:  2018-10-18T23:59:59
| MD5:   0149 9c50 05a0 f885 99d6 97fa 2b96 deb9
|_SHA-1: 99b0 3d08 bea3 6fe0 9c3f 8cb0 f891 13c6 1c9c 71e6
| ssl-enum-ciphers:
|   TLSv1.0:
|     ciphers:
|       TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA (prime256v1) - A
|       TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA (prime256v1) - A
|     compressors:
|       NULL
|     cipher preference: server
|   TLSv1.1:
|     ciphers:
|       TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA (prime256v1) - A
|       TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA (prime256v1) - A
|     compressors:
|       NULL
|     cipher preference: server
|   TLSv1.2:
|     ciphers:
|       TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 (prime256v1) - A
|       TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256 (prime256v1) - A
|       TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256-draft (prime256v1) - A
|       TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA (prime256v1) - A
|       TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256 (prime256v1) - A
|       TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 (prime256v1) - A
|       TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA (prime256v1) - A
|       TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384 (prime256v1) - A
|     compressors:
|       NULL
|     cipher preference: server
|_  least strength: A

Nmap done: 1 IP address (1 host up) scanned in 3.60 seconds

Featured Post

NGINX Unit is dynamically configured using a REST API

There is no static configuration file. All configuration changes happen directly in memory. Configuration changes take effect without requir...