HTTPS is an extension of HTTP that ensures secure data transfer over the web using encryption protocols like TLS or SSL. It's vital for websites handling sensitive information, signified by a padlock icon in the browser's address bar.


Everything is ok

  https://www.bcr.md/ro/persoane-fizice

STATUS 200 OK
Header Value
Accept-Ranges bytes
Access-Control-Allow-Credentials true
Access-Control-Allow-Headers Accept, Accept-Language, Authorization, Client-Accept-Language, Content-Type, X-REQUEST-ID, X-GEORGE-API-VERSION, X-GEORGE-USER, X-ebsapi-Authentication, X-ebsapi-Accept, Range, cache-control, x-requested-with, gem-form-id
Access-Control-Allow-Methods PUT, GET, POST, DELETE, OPTIONS
Access-Control-Expose-Headers content-disposition
Access-Control-Max-Age 3600
Alt-Svc h3=":443"; ma=86400
Cache-Control max-age=10, stale-while-revalidate=600, stale-if-error=36000
Connection keep-alive
Content-Length 226796
Content-Type text/html; charset=utf-8
Date Sun, 13 Oct 2024 00:01:00 GMT
ETag "375ec-6242dcf323f63"
Last-Modified Fri, 11 Oct 2024 06:43:48 GMT
Server Apache
Service-Worker-Allowed /
Strict-Transport-Security max-age=31536000
Vary Accept-Encoding
Via 1.1 dc8d59dd465eb0695e94a008d8f8d96e.cloudfront.net (CloudFront)
X-Amz-Cf-Id u5IH-TgTuyJnxSsw4bTqqy5oUlNKAQYWQ8g1-L-Sy07nGDR-gwyvvw==
X-Amz-Cf-Pop SOF50-P1
X-Cache Hit from cloudfront
X-Content-Type-Options nosniff
X-Powered-By 3
X-XSS-Protection 1; mode=block

  https://www.bcr.md

STATUS 301 Moved Permanently
Header Value
Access-Control-Allow-Credentials true
Access-Control-Allow-Headers Accept, Accept-Language, Authorization, Client-Accept-Language, Content-Type, X-REQUEST-ID, X-GEORGE-API-VERSION, X-GEORGE-USER, X-ebsapi-Authentication, X-ebsapi-Accept, Range, cache-control, x-requested-with, gem-form-id
Access-Control-Allow-Methods PUT, GET, POST, DELETE, OPTIONS
Access-Control-Expose-Headers content-disposition
Access-Control-Max-Age 3600
Age 1
Alt-Svc h3=":443"; ma=86400
Cache-Control max-age=86400
Connection keep-alive
Content-Length 245
Content-Type text/html; charset=iso-8859-1
Date Sun, 13 Oct 2024 00:00:59 GMT
Location https://www.bcr.md/ro/persoane-fizice
Server Apache
Strict-Transport-Security max-age=31536000
Via 1.1 dc8d59dd465eb0695e94a008d8f8d96e.cloudfront.net (CloudFront)
X-Amz-Cf-Id oddWvboHPfq45OCnCxXIfCXo31i1Hy-_XWGTh7nFY-rivsH5B2fG_g==
X-Amz-Cf-Pop SOF50-P1
X-Cache Hit from cloudfront
X-Powered-By 2

  https://bcr.md

STATUS 301 Moved Permanently
Header Value
Connection keep-alive
Content-Length 0
Content-Type application/octet-stream
Date Sun, 13 Oct 2024 00:00:59 GMT
Location https://www.bcr.md
Server global

HTTPS is properly configured

When HTTPS is set up correctly, it ensures secure communication between a website and its visitors. This is achieved through the use of a valid SSL/TLS certificate, which encrypts data exchanged between the user's browser and the server. Security headers like Content Security Policy (CSP) and HTTP Strict Transport Security (HSTS) are in place to enhance protection against cyber threats. All resources on the website are loaded securely over HTTPS, preventing mixed content issues. This not only improves security but also boosts the website's SEO ranking and builds trust with users, as indicated by the padlock icon in the browser's address bar.