generated: '2026-07-27' method: probed source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts hosts: - host: www.nspower.ca https: true tls_version: TLSv1.3 cert_expires: Nov 4 23:59:59 2026 GMT hsts: true hsts_max_age: 31536000 - host: greenbutton.nspower.ca https: true tls_version: TLSv1.3 cert_expires: Sep 24 18:03:48 2026 GMT hsts: null - host: accounts.nspower.ca https: true tls_version: TLSv1.3 cert_expires: Oct 19 18:43:19 2026 GMT hsts: true hsts_max_age: 31536000 hsts_directives: includeSubDomains; preload note: LoginRadius-hosted customer identity provider (SAML IdP). - host: myaccount.nspower.ca https: true tls_version: TLSv1.3 cert_expires: Oct 19 19:43:22 2026 GMT hsts: true hsts_max_age: 31536000 hsts_directives: includeSubDomains; preload - host: oasis.nspower.ca https: true tls_version: TLSv1.3 cert_expires: Oct 3 22:47:21 2026 GMT hsts: null note: >- 301s every path to https://www.nspower.ca/oasis — a vanity redirect, not a site. - host: outagemap.nspower.ca https: true tls_version: TLSv1.3 cert_expires: Nov 19 23:59:59 2026 GMT hsts: null note: KUBRA-hosted outage map; HTTP/2, CDN-fronted. - host: greenbuttonuat.nspower.ca https: false tls_version: TLSv1.3 cert_expires: Sep 21 16:02:00 2026 GMT hsts: null note: >- A UAT environment exists and negotiates TLS, but the certificate carries no subject alternative name matching this host, so a normal client closes the connection. Not a usable public surface. hosts_note: >- The first two hosts were probed by 0-working/probe-domain-security.py from the apis.yml properties; the remaining five were probed by hand on 2026-07-27 with the same technique (TLS handshake + HTTP HEAD) to cover every Nova Scotia Power host found during contract discovery. domains: - domain: nspower.ca dnssec: false caa: [] spf: true dmarc: true dmarc_policy: reject