HTTP/1.1 200 OK
server: nginx/1.24.0
content-type: text/html; charset=UTF-8
vary: Accept-Encoding
cache-control: no-cache, private
date: Fri, 24 Jan 2025 21:20:31 GMT
permissions-policy: accelerometer=(self), autoplay=(self), camera=(self), cross-origin-isolated=(self), display-capture=(self), encrypted-media=(self), fullscreen=(self), geolocation=(self), gyroscope=(self), magnetometer=(self), microphone=(self), midi=(self), payment=(self), picture-in-picture=*, publickey-credentials-get=(self), screen-wake-lock=(self), sync-xhr=*, usb=(self), xr-spatial-tracking=(self)
strict-transport-security: max-age=31536000; includeSubDomains; preload
expect-ct: max-age=2147483648
x-content-type-options: nosniff
x-download-options: noopen
x-frame-options: sameorigin
x-permitted-cross-domain-policies: master-only
x-xss-protection: 1; mode=block
referrer-policy: strict-origin
cross-origin-embedder-policy: unsafe-none
cross-origin-opener-policy: unsafe-none
cross-origin-resource-policy: cross-origin
set-cookie: XSRF-TOKEN=eyJpdiI6IkgxWE9NZlZZS253ZStLbnovMGdxcUE9PSIsInZhbHVlIjoiWmtLOHNUTHptQVhUZzRQSzJDcTF0N1gvc1c2YXlxUkpxYWloWlloN2RySEVKZ29abDJ0NnIwYUJvM3ljYjh3V3BiUTlRUDRqN1hnbGNCZUxqTFBQUU9VeVY3ODhuVHNjNHVHeXNkR0tuRUkzS3luL1cvcWxobExpSlh3QndrSFAiLCJtYWMiOiIwZmViZTk0YjAzMDhhNzkxOWY2YWNiZTJjNWZkMjk4NGVkZDc3MzIwYmI1NzE5OWZmOGRiNjI1N2I4YzQ4YjkxIiwidGFnIjoiIn0%3D; expires=Fri, 24 Jan 2025 23:20:31 GMT; Max-Age=7200; path=/; secure; samesite=lax
set-cookie: cimb_niaga_auto_finance_session=eyJpdiI6Iit4YXh3OXh4eEhGZTFJMlpwK0cxTkE9PSIsInZhbHVlIjoiYXNSdURybGhhK3RkcnpwU2krQW1ZUXNZQ0NvcXBrNC9STVpFVmt5VVc1OFhtWXk1eW42djd3TVVGZHZFMER2cHpkNjdENWtTT3JpNFgyNkFlRHVKOXdrVGJQNHgyejZyTG1VZy9IOWQvMTZsamR4SnJkVkh2UE1seFRxZ3pyU04iLCJtYWMiOiJkODU4OWUzOTRmMzUwZGI5NTljZDBiMWQxNjI4N2RmYzhlOGE1OTI0OTY1YjUwNzQ3ZDhmNjQ2NWVjOTBlODJlIiwidGFnIjoiIn0%3D; expires=Fri, 24 Jan 2025 23:20:31 GMT; Max-Age=7200; path=/; secure; httponly; samesite=lax
via: 1.1 google
Content-Security-Policy: default-src 'self' www.youtube.com www.google.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' cdnjs.cloudflare.com www.google.com code.jquery.com cdn.jsdelivr.net unpkg.com maps.google.com npmcdn.com cnaf-cms.storage.googleapis.com www.gstatic.com www.google-analytics.com www.googletagmanager.com www.youtube.com static.doubleclick.net; style-src 'self' 'unsafe-inline' cdnjs.cloudflare.com unpkg.com cnaf-cms.storage.googleapis.com www.gstatic.com www.youtube.com fonts.googleapis.com; img-src 'self' https://i.ibb.co/yn9wz60/Untitled-1.png maps.gstatic.com maps.google.com cnaf-cms.storage.googleapis.com storage.googleapis.com www.w3.org i.ytimg.com www.youtube.com yt3.ggpht.com data:; font-src 'self' cnaf-cms.storage.googleapis.com cdnjs.cloudflare.com fonts.gstatic.com fonts.googleapis.com; connect-src 'self' maps.googleapis.com googleads.g.doubleclick.net www.youtube.com jnn-pa.googleapis.com www.google-analytics.com; report-to groupname; form-action 'self'; manifest-src 'self' cnaf-cms.storage.googleapis.com;
Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
Transfer-Encoding: chunked
SSL Certificate
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
03:a8:87:75:05:7e:41:ba:d3:0b:f9:e4:98:77:56:a8
Signature Algorithm: sha256WithRSAEncryption
Issuer: C=US, O=DigiCert Inc, CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1
Validity
Not Before: Jan 13 00:00:00 2025 GMT
Not After : Feb 13 23:59:59 2026 GMT
Subject: C=ID, ST=Banten, L=Tangerang Selatan, O=PT Cimb Niaga Auto Finance, CN=*.cnaf.co.id
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:8a:c2:ce:ce:14:f2:d4:22:69:9f:e9:80:45:b6:
12:15:06:b1:5d:31:d9:c6:71:0f:c7:95:1a:de:7d:
a6:8f:57:26:3d:eb:93:e5:63:19:63:a3:fa:f5:19:
bb:72:ca:7c:d7:91:99:05:90:fb:88:60:3d:96:30:
58:dc:2a:13:c7:81:96:6f:7b:4f:88:ba:f7:49:6c:
9e:a1:b3:22:5f:56:b4:92:ab:54:0b:11:cf:3e:87:
2b:66:ac:96:57:26:ea:dd:6d:ca:f5:a9:d8:c6:11:
c9:1e:46:d9:31:f6:d9:a0:ae:d6:a8:1b:52:19:b8:
f1:8f:4e:2f:64:32:9b:b3:4c:ed:30:22:22:fc:77:
ec:3a:e8:ee:4e:57:36:02:bf:3d:ce:a7:7c:dc:44:
3d:ee:d9:4c:11:e3:d9:95:b8:57:aa:aa:be:70:ec:
52:71:f6:09:1d:45:07:c1:cf:bb:c2:08:0c:a4:03:
f2:d5:4b:d4:3c:9c:7c:c6:a6:b1:37:cd:ef:d1:b3:
48:fb:d6:7f:9d:35:1c:60:e9:e1:d6:4d:1e:a0:f4:
4c:81:0c:5d:bf:6a:63:be:d7:c1:b1:8a:67:16:f1:
24:17:e0:91:47:a2:75:78:94:a8:f4:3b:3e:d3:ae:
67:f5:21:cd:ee:5f:7e:47:36:c9:43:bf:4b:d6:b0:
71:15
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Authority Key Identifier:
74:85:80:C0:66:C7:DF:37:DE:CF:BD:29:37:AA:03:1D:BE:ED:CD:17
X509v3 Subject Key Identifier:
B2:D5:2B:C5:40:03:2A:E2:A0:1D:87:1E:CF:EB:BB:89:E1:43:3C:5E
X509v3 Subject Alternative Name:
DNS:*.cnaf.co.id, DNS:cnaf.co.id
X509v3 Certificate Policies:
Policy: 2.23.140.1.2.2
CPS: http://www.digicert.com/CPS
X509v3 Key Usage: critical
Digital Signature, Key Encipherment
X509v3 Extended Key Usage:
TLS Web Server Authentication, TLS Web Client Authentication
X509v3 CRL Distribution Points:
Full Name:
URI:http://crl3.digicert.com/DigiCertGlobalG2TLSRSASHA2562020CA1-1.crl
Full Name:
URI:http://crl4.digicert.com/DigiCertGlobalG2TLSRSASHA2562020CA1-1.crl
Authority Information Access:
OCSP - URI:http://ocsp.digicert.com
CA Issuers - URI:http://cacerts.digicert.com/DigiCertGlobalG2TLSRSASHA2562020CA1-1.crt
X509v3 Basic Constraints: critical
CA:FALSE
CT Precertificate SCTs:
Signed Certificate Timestamp:
Version : v1 (0x0)
Log ID : 96:97:64:BF:55:58:97:AD:F7:43:87:68:37:08:42:77:
E9:F0:3A:D5:F6:A4:F3:36:6E:46:A4:3F:0F:CA:A9:C6
Timestamp : Jan 13 07:39:41.032 2025 GMT
Extensions: none
Signature : ecdsa-with-SHA256
30:45:02:20:72:ED:BC:C0:FF:96:2E:1E:AC:8B:01:F1:
4D:5D:39:D0:D7:F9:E4:F8:78:88:1E:E8:AB:E4:FF:BF:
8C:92:31:3A:02:21:00:D8:4E:D9:C9:CD:6C:C9:75:49:
C1:79:75:9A:A3:8C:56:40:3E:00:7E:60:52:26:4C:92:
72:ED:E0:07:F7:95:42
Signed Certificate Timestamp:
Version : v1 (0x0)
Log ID : 64:11:C4:6C:A4:12:EC:A7:89:1C:A2:02:2E:00:BC:AB:
4F:28:07:D4:1E:35:27:AB:EA:FE:D5:03:C9:7D:CD:F0
Timestamp : Jan 13 07:39:41.021 2025 GMT
Extensions: none
Signature : ecdsa-with-SHA256
30:46:02:21:00:E9:53:27:AF:5B:38:F9:3E:F0:F2:5E:
4B:04:1E:62:98:74:E1:A5:76:9D:A3:00:4C:E3:B8:41:
85:F5:D1:FA:0E:02:21:00:B8:15:F3:6D:8D:10:61:9D:
1E:A7:77:2C:73:14:F2:29:0B:BC:E6:05:06:FA:09:E4:
60:D9:42:21:27:C9:5D:DF
Signed Certificate Timestamp:
Version : v1 (0x0)
Log ID : 49:9C:9B:69:DE:1D:7C:EC:FC:36:DE:CD:87:64:A6:B8:
5B:AF:0A:87:80:19:D1:55:52:FB:E9:EB:29:DD:F8:C3
Timestamp : Jan 13 07:39:41.038 2025 GMT
Extensions: none
Signature : ecdsa-with-SHA256
30:44:02:20:59:1E:AE:C7:3B:D7:9B:03:2A:6D:7D:B9:
42:B0:EF:46:7D:13:CC:76:C3:0B:AD:B1:B9:7B:BE:3D:
C8:46:CD:47:02:20:4E:A5:A4:B6:84:7A:7F:E9:0B:39:
E1:F6:77:54:0F:AB:4C:BF:2E:B1:C4:8E:CC:76:9B:3E:
3C:98:13:4F:DA:B6
Signature Algorithm: sha256WithRSAEncryption
Signature Value:
a5:5e:c1:85:57:45:0b:30:12:58:c5:17:e0:9d:df:a3:38:44:
63:73:ef:db:8d:ee:c4:9b:03:bb:a2:48:fc:1e:4d:26:0f:bd:
e3:7a:0d:75:cd:ab:f6:6f:af:f0:d7:db:cb:9d:60:01:08:25:
37:6c:78:a3:df:ab:9f:91:ee:d4:c4:fe:01:17:46:96:28:4c:
c1:86:bf:a8:50:80:7b:56:bc:da:fc:3d:83:04:af:41:b4:8e:
66:95:cf:4d:bd:f2:fd:12:dc:c8:a4:37:72:40:cf:38:c5:4b:
84:a9:fa:12:fa:a0:e3:ab:d2:02:82:0e:36:9e:59:0f:d1:4f:
ec:59:33:49:da:54:42:96:43:90:6e:40:d3:08:f6:fb:91:30:
74:c6:39:36:8c:79:ca:b2:f9:2d:91:d0:3a:d8:7c:31:f1:bc:
fb:6c:b2:21:31:23:39:5b:ab:ba:f3:e5:4e:07:5a:d5:08:17:
2d:a6:9e:39:e5:4d:5e:6d:3d:92:23:38:25:5d:6e:50:3a:37:
13:bf:b9:c9:ef:c4:15:8f:8b:d2:ce:f2:33:c4:f4:14:75:3f:
bc:c5:e3:ac:7a:1d:d7:6f:a2:e4:25:a2:f0:61:7f:22:c2:87:
52:42:ee:f4:e4:3e:20:32:c6:9a:95:cf:53:52:9a:21:19:e3:
67:8b:d1:49