Apache HTTP Server
Apache mod_ssl delegates TLS to OpenSSL. A hybrid group must be supported by the library in the deployed server and permitted by its effective virtual-host settings.
Evidence to collect
- Identify the exact Apache package, loaded SSL module, and linked library.
- Review SSLOpenSSLConfCmd and the documentation for the installed OpenSSL release before changing named groups.
- Check the public hostname and any independently terminated backend connection. A frontend result does not prove the backend uses the same cryptography.
Read-only inventory
Run this in the environment used by the application. Missing commands mean the tool is unavailable. This output is inventory, not a negotiation result.
httpd -vRecord the scope and result
Record the tested component, client, peer, protocol, selected algorithm, and date. Keep observed negotiation, documented capability, and unknown distinct. A failed check can reflect local tooling, certificate validation, network policy, or configuration; it does not prove that all PQC is unsupported.
Official references
Guidance reviewed 24 September 2026. Verify documentation for your deployed release; vendor capabilities and defaults change.