Web encryption of the .fr parc
What a browser gets when it opens a .fr address, before the page itself.
The first reading is being published.
Method
- The panel
- The same panel as the other .fr indices: 15,000 domains drawn at random from Afnic's open data file, which lists the 4,590,553 active .fr domains. The draw orders every domain by the sha256 fingerprint of its name, and the published seed is enough to rebuild it.
- The cadence
- Every domain is called on Monday, in the weekly sweep that already opens the panel. The panel stays the same from one week to the next: a movement in the series is the parc deciding.
- The reading
- The verdict comes from a TLS handshake made against port 443 of the drawn domain, and not from the page it ends up serving. A great many .fr domains send their root to another host, and a certificate read after the redirect belongs to the destination: the separate handshake is what guarantees the certificate judged is the domain's own.
- The HSTS header
- Strict-Transport-Security is counted on the answers that came back over TLS, that is on the ones that could carry it. A site offering HTTPS and a site imposing it are two different claims, and this share publishes the second.
- The API
GET https://api.stileex.xyz/v1/series/fr/web-encryption-share/latest
Measured on the same panel, in the same weekly sweep: WordPress patch lag in France and What the .fr parc is built on