TLS and certificates
TLS cipher checker
See which cipher suite a web server agrees with a modern client, and whether it will still accept a broken one when nothing better is on offer. The cipher suite decides how traffic is encrypted and protected against tampering.
What this checks
- The suite, protocol version and ALPN protocol (such as
h2for HTTP/2) agreed in a normal handshake on port 443. - A second ClientHello, sent at TLS 1.2, listing only broken or weak suites: NULL (no encryption), export-grade, RC4, single DES, 3DES and anonymous key exchange.
- Whether the server picks one of those suites, and which, or turns the connection down.
What the result means
In TLS 1.2 and earlier, a suite names the key exchange, the encryption algorithm and the integrity check together, as in ECDHE-RSA-AES128-GCM-SHA256. TLS 1.3 cut the list to a handful of suites that all use authenticated encryption (AEAD) and left the broken ones out entirely, so weak suites are a problem of TLS 1.2 and older.
The probe offers nothing but weak suites, so a well-configured server finds no acceptable choice and ends the handshake. If it picks one, a client that supports the same suite could end up using it: RC4 and 3DES have practical attacks against them, NULL suites encrypt nothing, and anonymous suites skip server authentication, which leaves the connection open to interception.
A pass means the server refused every suite in the list. The negotiated suite in the result is the one a modern client is given; a weak-suite finding is about what the server will still agree with a client that asks for less.
How to fix common issues
Weak cipher suites accepted
Restrict the server to modern AEAD cipher suites (AES-GCM, ChaCha20-Poly1305). Mozilla's SSL Configuration Generator produces a correct configuration for most servers.
Cyber Essentials and ISO 27001
Which algorithms are acceptable is a decision ISO/IEC 27001:2022 leaves to the organisation, under Annex A 8.24 (use of cryptography). A refused weak-suite probe is technical evidence that one public service follows such a rule. The rule itself, its owner, how exceptions for old clients are approved and when it is reviewed have to be set and recorded by the organisation.
Scope and limitations
- This is not a cipher enumeration: it does not list every suite the server supports or the order it prefers them in.
- Suites outside the weak list, such as RSA key exchange without forward secrecy or AES in CBC mode, are not judged.
- The probe is a TLS 1.2 ClientHello. TLS 1.3 suites are not probed, since none of them is weak.
- Key sizes, Diffie-Hellman parameters and the strength of the certificate signature are outside this check.
Related guides
Questions
- What is a cipher suite?
- The set of algorithms a TLS connection uses. In TLS 1.2 it covers the key exchange, the bulk cipher and the message authentication; in TLS 1.3 only the cipher and hash, with key exchange agreed separately. Client and server settle on one during the handshake.
- Is 3DES still safe to use?
- No. Its 64-bit block size makes long-lived connections vulnerable to the Sweet32 attack, and it is much slower than AES. Remove it unless a specific legacy client depends on it, and plan to retire that client.
- Which cipher suites should a web server allow?
- For TLS 1.3, the defaults. For TLS 1.2, ECDHE key exchange with AES-GCM or ChaCha20-Poly1305. Mozilla's server-side TLS guidance and its configuration generator give tested settings for common servers.
Related security tools
- TLS version checker - See whether a server still accepts SSL 3.0, TLS 1.0 or TLS 1.1, and whether it offers TLS 1.3.
- SSL/TLS checker - Check a site's HTTPS, certificate, expiry, TLS versions and weak cipher suites.
- End-of-life software checker - See whether a site advertises software versions that no longer receive security fixes.
- Website security checker - Check a domain's DNS, email authentication, TLS, security headers and public technology in one pass.

