Skip to content

TLS and certificates

SSL/TLS checker

Test a website's HTTPS set-up in one run: whether it answers over TLS, whether its certificate is trusted and in date, which protocol versions it still accepts and whether it agrees to a weak cipher. Secure connections today use TLS; SSL is its broken predecessor, though the old name stuck.

Checked from Ironfang Security's scanner address with the same low-impact limits as a scan. Nothing you enter is kept.

What this checks

What the result means

SSL (Secure Sockets Layer) was the first protocol for encrypted web traffic. TLS (Transport Layer Security) replaced it in 1999, and SSL 2.0 and SSL 3.0 have both since been prohibited (RFC 6176, RFC 7568). A browser showing a secure connection today is using TLS 1.2 or TLS 1.3. "SSL" survives in product names and in "SSL certificate", which means the certificate a TLS server presents.

Results are listed per host, because the bare domain and its www. name can be served by different machines with different certificates. A pass means that one check found nothing to report. It does not show that the site, or the server behind it, is secure.

Certificate findings tend to be the urgent ones: an expired, untrusted or wrongly named certificate puts a full-page browser warning in front of every visitor. Obsolete versions and weak suites are less visible but hand an attacker on the network path known weaknesses to work with. A missing TLS 1.3 is a recommendation, since TLS 1.2 on its own remains acceptable.

How to fix common issues

Website is not available over HTTPS

Install a certificate and serve the site over HTTPS. Free certificates are available from Let's Encrypt, and most hosts and CDNs can provision them automatically.

More in the HTTPS availability check reference

Certificate has expired

Renew the certificate and install it. Automate renewal (for example with ACME/Let's Encrypt or your host's managed certificates) so it does not happen again.

More in the Certificate validity check reference

Certificate is not trusted

Install a certificate from a public certificate authority, and configure the server to send the full chain (your certificate plus intermediates).

More in the Certificate validity check reference

Certificate does not cover this hostname

Issue a certificate whose subject alternative names include this hostname, or a wildcard that covers it, and install it.

More in the Certificate validity check reference

TLS 1.0 is enabled

Configure the server to require TLS 1.2 or later. For nginx use ssl_protocols TLSv1.2 TLSv1.3;; for Apache SSLProtocol -all +TLSv1.2 +TLSv1.3. CDNs usually have a minimum TLS version setting.

More in the TLS protocol versions check reference

Weak cipher suites accepted

Restrict the server to modern AEAD cipher suites (AES-GCM, ChaCha20-Poly1305). Mozilla's SSL Configuration Generator produces a correct configuration for most servers.

More in the Cipher suites check reference

Cyber Essentials and ISO 27001

Cyber Essentials does not specify TLS versions or certificates. Its secure configuration theme does cover the internet-facing services in scope, and a run like this one is technical evidence of how one of those services is set up as the internet sees it.

In ISO/IEC 27001:2022 the nearest Annex A controls are 8.24 (use of cryptography) and 8.21 (security of network services). The organisation still has to decide its own TLS baseline, name an owner for each public service and review the settings when they change. The check shows the result at one moment, not that any of that is in place.

Scope and limitations

Related guides

Questions

Is SSL the same as TLS?
Not quite. TLS is the protocol that succeeded SSL, and every SSL version is now prohibited. People still say SSL out of habit, so an SSL checker in practice tests TLS.
Does an SSL checker test my server or my CDN?
Whatever answers on port 443 for the name. If a CDN or proxy handles TLS for the site, the results describe its configuration; the connection from it to your origin server cannot be seen from outside.
Is a site with a valid certificate safe?
A valid certificate shows that the connection is encrypted to a server holding a certificate for that name. It says nothing about the site itself, its software or how it handles data.

Related security tools