What it checks
Which protocol versions the server accepts: whether obsolete SSL 3.0, TLS 1.0 and TLS 1.1 are still enabled, and whether TLS 1.3 is offered.
TLS protocol versions. A pass means: Obsolete SSL and TLS versions are disabled.
TLS 1.3 support. A pass means: TLS 1.3 is supported.
Possible findings
SSL 3.0 is enabled
Severity: HighConfidence: ConfirmedKind: Security issue
What we found
The server accepted an SSL 3.0 connection.
Why it matters
SSL 3.0 is broken (POODLE) and was prohibited in 2015. No current browser needs it.
How to fix it
Disable SSL 3.0. For nginx use ssl_protocols TLSv1.2 TLSv1.3;; for Apache use SSLProtocol -all +TLSv1.2 +TLSv1.3.
TLS 1.0 is enabled
Severity: MediumConfidence: ConfirmedKind: Security issue
What we found
The server accepted a TLS 1.0 connection.
Why it matters
TLS 1.0 is obsolete and was formally deprecated in 2021. It lacks modern protections, and PCI DSS and most security baselines require it to be disabled.
How to fix it
Configure the server to require TLS 1.2 or later. For nginx use ssl_protocols TLSv1.2 TLSv1.3;; for Apache SSLProtocol -all +TLSv1.2 +TLSv1.3. CDNs usually have a minimum TLS version setting.
TLS 1.1 is enabled
Severity: MediumConfidence: ConfirmedKind: Security issue
What we found
The server accepted a TLS 1.1 connection.
Why it matters
TLS 1.1 is obsolete and was formally deprecated in 2021 alongside TLS 1.0.
How to fix it
Configure the server to require TLS 1.2 or later. For nginx use ssl_protocols TLSv1.2 TLSv1.3;; for Apache SSLProtocol -all +TLSv1.2 +TLSv1.3.
TLS 1.3 is not supported
Severity: InformationConfidence: ConfirmedKind: Recommended hardening
What we found
The server did not negotiate TLS 1.3.
Why it matters
TLS 1.3 is faster and removes legacy options that have caused vulnerabilities. TLS 1.2 remains acceptable, so this is a recommendation rather than a problem.
How to fix it
Enable TLS 1.3 alongside TLS 1.2. Recent versions of nginx, Apache, IIS (Windows Server 2022) and all major CDNs support it.

