Find your technology

The guide library

Start with the tools you actually use. Each guide explains the evidence you can collect and the questions that remain open.

Help me choose a check →

Operating systems

  • Android

    Android’s Conscrypt module provides platform cryptographic functionality, while applications may bundle another TLS stack. OS and app behavior must be assessed separately.

    TLS · beginner · Connection and capability guidance

  • ChromeOS

    ChromeOS browser traffic, Android apps, and Linux-container applications can use different TLS implementations and policies.

    TLS · beginner · Connection and capability guidance

  • iOS and iPadOS

    Browser transport, native application connections, and iMessage encryption are separate surfaces on Apple mobile devices.

    TLS · beginner · Connection and capability guidance

  • Linux

    Linux is not one TLS implementation. Distribution packages, application bundles, containers, and language runtimes may use different crypto libraries.

    TLS · beginner · Connection and capability guidance

  • macOS

    macOS applications may use Apple networking frameworks or bundled crypto libraries. A standalone OpenSSL result belongs to that tool, not automatically to Safari or other apps.

    TLS · beginner · Connection and capability guidance

  • Windows

    Use approved local tools for a verified TLS check on Windows, and distinguish browser, OpenSSL, Schannel, IIS, and application evidence.

    TLS · beginner · Connection and capability guidance

Servers

  • Apache HTTP Server

    Apache mod_ssl delegates TLS to OpenSSL. A hybrid group must be supported by the library in the deployed server and permitted by its effective virtual-host settings.

    TLS · operator · Connection and capability guidance

  • Caddy

    Caddy uses Go TLS. Go 1.24 introduced standardized X25519MLKEM768 support; the older Go 1.23 hybrid used a draft Kyber group. The Go toolchain used to build Caddy matters.

    TLS · operator · Connection and capability guidance

  • nginx

    Check nginx's actual SSL library and negotiated group, distinguish edge and origin connections, and stage a safe configuration change.

    TLS · operator · Connection and capability guidance

Cloud & CDN

  • AWS

    AWS services have distinct TLS endpoints and security-policy menus. CloudFront viewer connections, load balancer listeners, and origin connections must be assessed separately.

    TLS · operator · Connection and capability guidance

  • Azure

    Azure Front Door terminates client TLS and establishes a separate connection to the origin. Application Gateway, API Management, and application ingress have their own configuration and evidence requirements.

    TLS · operator · Connection and capability guidance

  • CDNs and hosted websites

    A static website or single-page application inherits transport security from the service terminating HTTPS. Application JavaScript cannot enable a TLS named group on the hosting provider.

    TLS · operator · Connection and capability guidance

  • Cloudflare

    Verify visitor-to-edge hybrid TLS, collect origin connection evidence, and review current Cloudflare key exchange settings.

    TLS · operator · Connection and capability guidance

  • Google Cloud

    Google Cloud load balancer TLS behavior depends on the load balancer type and supported SSL-policy configuration. Google’s consumer services are not evidence for every customer deployment.

    TLS · operator · Connection and capability guidance

Libraries & runtimes

  • BoringSSL

    BoringSSL is an application TLS library. Embedding applications choose their build and TLS configuration; another BoringSSL-based product’s behavior is not a guarantee for yours.

    TLS · technical · Connection and capability guidance

  • curl

    curl supports multiple TLS backends. Available command-line options and named groups depend on the installed build and backend.

    TLS · technical · Connection and capability guidance

  • .NET

    SslStream and HttpClient depend on platform TLS support. Windows, Linux, and Apple platforms do not share one universal OpenSSL configuration.

    TLS · technical · Connection and capability guidance

  • Go crypto/tls

    Go 1.24 introduced X25519MLKEM768 and enabled it in the default TLS configuration. Go 1.23 used the older draft Kyber hybrid. Explicit CurvePreferences and runtime settings can change defaults.

    TLS · technical · Connection and capability guidance

  • Java and JSSE

    Cryptographic primitive support and TLS integration are separate features. An ML-KEM KEM implementation does not by itself show that a JSSE provider supports hybrid TLS groups.

    TLS · technical · Connection and capability guidance

  • Node.js

    Run a native Node.js TLS diagnostic, preserve certificate validation, inspect actual key agreement, and investigate application-specific differences.

    TLS · technical · Connection and capability guidance

  • Network Security Services (NSS)

    NSS provides security libraries used by applications including Firefox. Application policy and the shipped NSS build determine the connection behavior.

    TLS · technical · Connection and capability guidance

  • Check post-quantum TLS with OpenSSL

    Identify your OpenSSL build, verify a hybrid TLS connection, interpret output, and troubleshoot without changing system libraries.

    TLS · technical · Connection and capability guidance

  • PHP

    PHP OpenSSL streams and PHP cURL can use different TLS integrations. The web server terminating inbound HTTPS is another independent component.

    TLS · technical · Connection and capability guidance

  • Python

    Python’s ssl module wraps OpenSSL. Different Python distributions can link or bundle different OpenSSL releases, independently of the executable on your PATH.

    TLS · technical · Connection and capability guidance

  • rustls

    rustls uses a CryptoProvider for cryptographic algorithms. Provider selection, build features, and configured key-exchange groups affect what an application can negotiate.

    TLS · technical · Connection and capability guidance

  • wolfSSL and embedded devices

    wolfSSL’s supported key-exchange groups depend on build configuration. Embedded devices also need sufficient resources and interoperable peers to complete the handshake.

    TLS · technical · Connection and capability guidance

Browsers

  • Google Chrome

    Chrome uses its own TLS implementation. Enterprise policy, platform, and the server all influence a particular connection.

    TLS · beginner · Connection and capability guidance

  • Microsoft Edge

    Edge connection behavior depends on the browser build, platform, enterprise policies, and the peer.

    TLS · beginner · Connection and capability guidance

  • Mozilla Firefox

    Firefox uses Mozilla security libraries. Version and policy indicate possible support, while a connection supplies evidence of negotiation.

    TLS · beginner · Connection and capability guidance

  • Safari

    Apple documents quantum-secure TLS for supported platform releases. Safari behavior must be checked on the actual operating system and network path.

    TLS · beginner · Connection and capability guidance

Apps & infrastructure

  • Email transport

    SMTP, IMAP, and POP use different ports and can start TLS immediately or upgrade using STARTTLS. Transport encryption does not establish end-to-end message encryption.

    TLS · technical · Connection and capability guidance

  • iMessage and PQ3

    Apple’s PQ3 design combines post-quantum initial key establishment with ongoing rekeying for iMessage. This is application encryption, separate from TLS to Apple services.

    Messaging · beginner · Vendor evidence guidance

  • OpenSSH

    Inspect OpenSSH capabilities and effective policy, observe a verified SSH handshake, and plan a safe server upgrade.

    SSH · technical · Connection and capability guidance

  • OpenVPN

    OpenVPN uses a TLS control channel and a separate data channel. A web TLS check cannot speak the VPN protocol or establish how the tunnel negotiated keys.

    VPN · technical · Vendor evidence guidance

  • Signal

    Signal documents PQXDH for initial session establishment and introduced the Sparse Post Quantum Ratchet (SPQR) in October 2025. Its Triple Ratchet combines that ratchet with the existing Double Ratchet.

    Messaging · beginner · Vendor evidence guidance

  • WhatsApp

    WhatsApp publishes its own encryption design. Use of the Signal Protocol does not mean every Signal feature or rollout is present in WhatsApp.

    Messaging · beginner · Vendor evidence guidance

  • WireGuard

    WireGuard’s protocol uses Curve25519 and can mix an optional pre-shared key into its handshake. The existence of that key does not establish how it was generated or exchanged.

    VPN · technical · Vendor evidence guidance