Skip to content

TLS and certificates

TLS version checker

Find out which protocol versions a web server will speak. The checker looks for obsolete versions that should be switched off (SSL 3.0, TLS 1.0 and TLS 1.1) and confirms whether TLS 1.3 is available alongside TLS 1.2.

Checked from Ironfang Security's scanner address with the same low-impact limits as a scan. Nothing you enter is kept.

What this checks

What the result means

The protocol version sets the rules for the whole connection: how keys are agreed, which ciphers are allowed and how the handshake itself is protected. SSL 3.0 is broken by the POODLE attack and was prohibited in 2015 (RFC 7568). TLS 1.0 and TLS 1.1 were deprecated in 2021 (RFC 8996), and current browsers no longer connect with them.

An old version left enabled rarely breaks anything for visitors, which is why it lingers. It still offers an attacker a weaker protocol to aim for, and baselines such as PCI DSS require early TLS to be turned off.

A pass on obsolete versions means all three probes were refused. A missing TLS 1.3 is reported as a hardening recommendation rather than a problem: TLS 1.2 with sound cipher suites remains acceptable, while TLS 1.3 connects in one round trip fewer and removes the legacy options behind past attacks.

How to fix common issues

SSL 3.0 is enabled

Disable SSL 3.0. For nginx use ssl_protocols TLSv1.2 TLSv1.3;; for Apache use SSLProtocol -all +TLSv1.2 +TLSv1.3.

More in the TLS protocol versions check reference

TLS 1.0 is enabled

Configure the server to require TLS 1.2 or later. For nginx use ssl_protocols TLSv1.2 TLSv1.3;; for Apache SSLProtocol -all +TLSv1.2 +TLSv1.3. CDNs usually have a minimum TLS version setting.

More in the TLS protocol versions check reference

TLS 1.1 is enabled

Configure the server to require TLS 1.2 or later. For nginx use ssl_protocols TLSv1.2 TLSv1.3;; for Apache SSLProtocol -all +TLSv1.2 +TLSv1.3.

More in the TLS protocol versions check reference

TLS 1.3 is not supported

Enable TLS 1.3 alongside TLS 1.2. Recent versions of nginx, Apache, IIS (Windows Server 2022) and all major CDNs support it.

More in the TLS 1.3 support check reference

Cyber Essentials and ISO 27001

Under ISO/IEC 27001:2022, a minimum TLS version belongs in a service's documented configuration (Annex A 8.9, configuration management) and in the organisation's rules on cryptography (8.24). The probes are technical evidence of what one server accepts now. Choosing the minimum, applying it to every service and revisiting it as clients change remain the organisation's job. Cyber Essentials does not name protocol versions; its secure configuration theme is the closest fit.

Scope and limitations

Related guides

Questions

Should I disable TLS 1.0 and TLS 1.1?
Yes. RFC 8996 retired both, and no current browser needs them. Anything that still depends on them is usually an old system, better upgraded than accommodated.
Do I need TLS 1.3?
It is recommended rather than required. TLS 1.2 with modern cipher suites is still acceptable, but TLS 1.3 is quicker to connect and leaves out options that caused earlier vulnerabilities. Current web servers and CDNs support it.
Why is TLS 1.2 shown as not tested?
When the server negotiates TLS 1.3, this checker does not open a separate TLS 1.2-only connection, so it cannot say whether 1.2 is also accepted. Most servers keep TLS 1.2 on for clients that lack 1.3.

Related security tools