Find your technology
The guide library
Start with the tools you actually use. Each guide explains the evidence you can collect and the questions that remain open.
Operating systems
Android
Android’s Conscrypt module provides platform cryptographic functionality, while applications may bundle another TLS stack. OS and app behavior must be assessed separately.
TLS · beginner · Connection and capability guidance
ChromeOS
ChromeOS browser traffic, Android apps, and Linux-container applications can use different TLS implementations and policies.
TLS · beginner · Connection and capability guidance
iOS and iPadOS
Browser transport, native application connections, and iMessage encryption are separate surfaces on Apple mobile devices.
TLS · beginner · Connection and capability guidance
Linux
Linux is not one TLS implementation. Distribution packages, application bundles, containers, and language runtimes may use different crypto libraries.
TLS · beginner · Connection and capability guidance
macOS
macOS applications may use Apple networking frameworks or bundled crypto libraries. A standalone OpenSSL result belongs to that tool, not automatically to Safari or other apps.
TLS · beginner · Connection and capability guidance
Windows
Use approved local tools for a verified TLS check on Windows, and distinguish browser, OpenSSL, Schannel, IIS, and application evidence.
TLS · beginner · Connection and capability guidance
Servers
Apache HTTP Server
Apache mod_ssl delegates TLS to OpenSSL. A hybrid group must be supported by the library in the deployed server and permitted by its effective virtual-host settings.
TLS · operator · Connection and capability guidance
Caddy
Caddy uses Go TLS. Go 1.24 introduced standardized X25519MLKEM768 support; the older Go 1.23 hybrid used a draft Kyber group. The Go toolchain used to build Caddy matters.
TLS · operator · Connection and capability guidance
nginx
Check nginx's actual SSL library and negotiated group, distinguish edge and origin connections, and stage a safe configuration change.
TLS · operator · Connection and capability guidance
Cloud & CDN
AWS
AWS services have distinct TLS endpoints and security-policy menus. CloudFront viewer connections, load balancer listeners, and origin connections must be assessed separately.
TLS · operator · Connection and capability guidance
Azure
Azure Front Door terminates client TLS and establishes a separate connection to the origin. Application Gateway, API Management, and application ingress have their own configuration and evidence requirements.
TLS · operator · Connection and capability guidance
CDNs and hosted websites
A static website or single-page application inherits transport security from the service terminating HTTPS. Application JavaScript cannot enable a TLS named group on the hosting provider.
TLS · operator · Connection and capability guidance
Cloudflare
Verify visitor-to-edge hybrid TLS, collect origin connection evidence, and review current Cloudflare key exchange settings.
TLS · operator · Connection and capability guidance
Google Cloud
Google Cloud load balancer TLS behavior depends on the load balancer type and supported SSL-policy configuration. Google’s consumer services are not evidence for every customer deployment.
TLS · operator · Connection and capability guidance
Libraries & runtimes
BoringSSL
BoringSSL is an application TLS library. Embedding applications choose their build and TLS configuration; another BoringSSL-based product’s behavior is not a guarantee for yours.
TLS · technical · Connection and capability guidance
curl
curl supports multiple TLS backends. Available command-line options and named groups depend on the installed build and backend.
TLS · technical · Connection and capability guidance
.NET
SslStream and HttpClient depend on platform TLS support. Windows, Linux, and Apple platforms do not share one universal OpenSSL configuration.
TLS · technical · Connection and capability guidance
Go crypto/tls
Go 1.24 introduced X25519MLKEM768 and enabled it in the default TLS configuration. Go 1.23 used the older draft Kyber hybrid. Explicit CurvePreferences and runtime settings can change defaults.
TLS · technical · Connection and capability guidance
Java and JSSE
Cryptographic primitive support and TLS integration are separate features. An ML-KEM KEM implementation does not by itself show that a JSSE provider supports hybrid TLS groups.
TLS · technical · Connection and capability guidance
Node.js
Run a native Node.js TLS diagnostic, preserve certificate validation, inspect actual key agreement, and investigate application-specific differences.
TLS · technical · Connection and capability guidance
Network Security Services (NSS)
NSS provides security libraries used by applications including Firefox. Application policy and the shipped NSS build determine the connection behavior.
TLS · technical · Connection and capability guidance
Check post-quantum TLS with OpenSSL
Identify your OpenSSL build, verify a hybrid TLS connection, interpret output, and troubleshoot without changing system libraries.
TLS · technical · Connection and capability guidance
PHP
PHP OpenSSL streams and PHP cURL can use different TLS integrations. The web server terminating inbound HTTPS is another independent component.
TLS · technical · Connection and capability guidance
Python
Python’s ssl module wraps OpenSSL. Different Python distributions can link or bundle different OpenSSL releases, independently of the executable on your PATH.
TLS · technical · Connection and capability guidance
rustls
rustls uses a CryptoProvider for cryptographic algorithms. Provider selection, build features, and configured key-exchange groups affect what an application can negotiate.
TLS · technical · Connection and capability guidance
wolfSSL and embedded devices
wolfSSL’s supported key-exchange groups depend on build configuration. Embedded devices also need sufficient resources and interoperable peers to complete the handshake.
TLS · technical · Connection and capability guidance
Browsers
Google Chrome
Chrome uses its own TLS implementation. Enterprise policy, platform, and the server all influence a particular connection.
TLS · beginner · Connection and capability guidance
Microsoft Edge
Edge connection behavior depends on the browser build, platform, enterprise policies, and the peer.
TLS · beginner · Connection and capability guidance
Mozilla Firefox
Firefox uses Mozilla security libraries. Version and policy indicate possible support, while a connection supplies evidence of negotiation.
TLS · beginner · Connection and capability guidance
Safari
Apple documents quantum-secure TLS for supported platform releases. Safari behavior must be checked on the actual operating system and network path.
TLS · beginner · Connection and capability guidance
Apps & infrastructure
Email transport
SMTP, IMAP, and POP use different ports and can start TLS immediately or upgrade using STARTTLS. Transport encryption does not establish end-to-end message encryption.
TLS · technical · Connection and capability guidance
iMessage and PQ3
Apple’s PQ3 design combines post-quantum initial key establishment with ongoing rekeying for iMessage. This is application encryption, separate from TLS to Apple services.
Messaging · beginner · Vendor evidence guidance
OpenSSH
Inspect OpenSSH capabilities and effective policy, observe a verified SSH handshake, and plan a safe server upgrade.
SSH · technical · Connection and capability guidance
OpenVPN
OpenVPN uses a TLS control channel and a separate data channel. A web TLS check cannot speak the VPN protocol or establish how the tunnel negotiated keys.
VPN · technical · Vendor evidence guidance
Signal
Signal documents PQXDH for initial session establishment and introduced the Sparse Post Quantum Ratchet (SPQR) in October 2025. Its Triple Ratchet combines that ratchet with the existing Double Ratchet.
Messaging · beginner · Vendor evidence guidance
WhatsApp
WhatsApp publishes its own encryption design. Use of the Signal Protocol does not mean every Signal feature or rollout is present in WhatsApp.
Messaging · beginner · Vendor evidence guidance
WireGuard
WireGuard’s protocol uses Curve25519 and can mix an optional pre-shared key into its handshake. The existence of that key does not establish how it was generated or exchanged.
VPN · technical · Vendor evidence guidance