Check · Transport security · default severity critical
TLS certificate validity
What Kavach checks
Whether the certificate is trusted by browsers and matches the hostname.
Why it matters
An invalid or mismatched certificate lets an attacker impersonate your site, and throws the scary 'Not secure' warning that scares real users away.
How an attacker uses it
- Attacker sets up a lookalike server for your domain.
- With no valid cert, the browser can't tell real from fake.
- Victim's traffic is silently decrypted and modified in transit.
How to fix it
Install a valid certificate from a trusted CA (free via Let's Encrypt) covering this exact hostname, and keep the chain complete.
Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare
Limitations
This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 1.