Series 02 of 20 -- Government Online

.gov.lk and Legacy Web Security

Government portals are where citizens submit forms, log in, and interact with state services. When those portals expose port 80 without enforcing HTTPS redirects, data submitted over that connection travels without TLS encryption. Whether that applies to any specific host depends on its redirect and application configuration. Here is what the public index shows for .gov.lk.

30 .gov.lk Hosts
on Port 80
121 Indexed Deprecated
TLS Associations
18 Windows
Servers
5 ISPs Hosting
Gov Infrastructure

The Queries

Two queries were run against publicly accessible internet indexing data. The first, hostname:.gov.lk port:80, returned 30 indexed results: .gov.lk hostnames with port 80 observable at the time of indexing. The second, ssl.cert.subject.cn:*.gov.lk ssl.version:TLSv1,SSLv2,SSLv3, returned 121 indexed results: results associated with .gov.lk certificates where the observed service advertised deprecated protocol support.

These two queries measure different things. The first identifies hosts where HTTP is observable. The second identifies hosts where the TLS handshake advertises protocol versions that have been deprecated by standards bodies and disabled by default in major browsers. A host may appear in both.

Methodology Note All results are from publicly accessible internet indexing data. Port observations and TLS version data reflect index snapshots and may not represent the current state of any specific host. TLS version data reflects what the server advertises as supported, not necessarily what it accepts or uses by default. No systems were accessed or probed.

Port 80: HTTP-Observable .gov.lk Hosts

30 .gov.lk hosts were indexed with port 80 observable. A service observed on port 80 is reachable over plaintext HTTP. Whether sensitive application traffic is actually exposed depends on redirect and application configuration; some hosts may redirect all traffic to HTTPS, others may not. The observation establishes that a plaintext HTTP service is present and indexed, not that HTTPS is absent.

Apache httpd leads by a wide margin, accounting for 18 of the 30 indexed results. Microsoft IIS httpd follows at 4.

Products on Port 80 (.gov.lk)
Identified from public index banners · 30 total results
Apache httpd
18
Microsoft IIS httpd
4
nginx
3
Lotus Domino
1
MS HTTPAPI httpd
1

Lotus Domino is worth noting. The public index identified one .gov.lk port 80 host as running it. Lotus Domino's vendor support status varies by version; the relevant question for the responsible administrator is whether the specific version in use is still receiving security updates.

Organizations Hosting Port 80 .gov.lk Infrastructure

Top Organizations (.gov.lk, Port 80)
By indexed result count
ISP Sri Lanka*
11
SL Telecom IDC
10
Internet Data Center
4
Lanka Gov Cloud
2
ICT Agency
1

* "Internet Service Provider in Sri Lanka" appears as two variants in the index, combined total shown

The organization field labeled as government cloud infrastructure appears in the port 80 results. Hosts on government-designated infrastructure appearing on port 80 warrants review by the responsible administrators.

Deprecated Protocol Support: 121 Indexed .gov.lk Services

The second query identified 121 indexed results where an indexed TLS service associated with a .gov.lk certificate was observed advertising SSLv3, SSLv2, or TLSv1. These protocol versions were deprecated by the IETF and have been disabled by default in all major browsers. SSLv3 was broken by the POODLE vulnerability in 2014. TLSv1 and TLSv1.1 were formally deprecated in 2018. These results reflect what was observed in the index at the time of collection and may not represent the current state of any specific host.

A certificate advertising deprecated protocol support does not establish that those protocols are the default or that encryption is absent. It indicates deprecated protocol support was observed in the indexed data at the time of collection. For government-facing infrastructure, TLS 1.2 or newer should be supported with deprecated protocols disabled; TLS 1.3 should be enabled where compatible.

Top Organizations (.gov.lk, Deprecated TLS)
ssl.cert.subject.cn:*.gov.lk ssl.version:TLSv1,SSLv2,SSLv3 · 121 total results
Lanka Gov Cloud
30
SL Telecom IDC
24
ISP Sri Lanka*
18
Dialog Telekom
17
ISP Sri Lanka (alt)
11

* Two organization name variants combined

The organization field labeled as government cloud infrastructure accounts for 30 of 121 results, the largest single organization. 24 more sit within Sri Lanka Telecom's Internet Data Center. The bulk of .gov.lk indexed deprecated TLS associations is concentrated in a small number of hosting providers.

Top Products (.gov.lk, Deprecated TLS)
Identified from public index banners
Apache httpd
45
nginx
22
MS HTTPAPI httpd
11
Microsoft IIS httpd
7
AWS ELB
1

End-of-Life Software in Government Infrastructure

The index auto-tags hosts based on observed behavior. Within the deprecated TLS results, a meaningful subset carried the eol-product tag, indicating software the vendor has stopped maintaining. The combination of deprecated TLS support and end-of-life software on the same host is the pattern of most concern: configuration weaknesses on a platform that will not receive security updates.

A recurring pattern in the data is government mail servers running Horde webmail. Horde components identified in the indexed data were associated with an end-of-life product classification by the index. Multiple .gov.lk mail servers running Horde appeared in the deprecated TLS results. The combination of an end-of-life product classification and observed deprecated TLS associations on mail infrastructure is a pattern worth flagging for administrators.

Notable Patterns

Government and emergency service infrastructure observed in the indexed results:

Critical Public-Service Portal
Legacy TLS and EOL Software
A critical public-service portal appeared in the indexed results where an indexed TLS service associated with its certificate was observed advertising SSLv3 alongside newer protocol versions, and carrying an end-of-life product tag. Infrastructure of this type carrying these configuration patterns warrants priority review.
Senior Public-Sector Portal
No TLSv1.3 Indicated
A senior public-sector portal appeared in the indexed results where an indexed TLS service associated with its certificate was observed advertising TLSv1, TLSv1.1, and TLSv1.2, with no TLSv1.3 support indicated. This is consistent with the wider pattern across the dataset: TLSv1.2 is present but TLSv1.3 adoption among .gov.lk hosts is limited. Portals handling government-to-citizen communications should be leading on current protocol support, not trailing.
Pattern: Government Mail
Legacy Webmail on .gov.lk Mail Servers
Several .gov.lk mail servers running Horde webmail appeared in both the deprecated TLS and end-of-life product results. Horde components identified in the indexed data carried an end-of-life product classification. The combination of an end-of-life product classification and observed deprecated TLS support represents a larger potential attack surface than either condition alone.

Summary

30 .gov.lk hosts indexed on port 80. 121 indexed services observed advertising deprecated TLS protocol support. The organization field labeled as government cloud infrastructure accounts for the largest share of the second result set. The dataset does not establish active exploitation. It establishes that the configuration patterns are present, indexed, and observable to anyone who looks.

Government portals are not ordinary websites. They handle citizen identity, financial transactions, and public records. The appropriate standard is current TLS across all public-facing services, with deprecated protocol support disabled and end-of-life software replaced. The editorial rule for this series applies here as everywhere: public data only, patterns not targets. No IP addresses, no hostnames, no information that functions as a reconnaissance aid.