← Knowledge base

Apache HTTP Server

Apache mod_ssl delegates TLS to OpenSSL. A hybrid group must be supported by the library in the deployed server and permitted by its effective virtual-host settings.

Evidence to collect

  1. Identify the exact Apache package, loaded SSL module, and linked library.
  2. Review SSLOpenSSLConfCmd and the documentation for the installed OpenSSL release before changing named groups.
  3. Check the public hostname and any independently terminated backend connection. A frontend result does not prove the backend uses the same cryptography.

Read-only inventory

Run this in the environment used by the application. Missing commands mean the tool is unavailable. This output is inventory, not a negotiation result.

httpd -v

Record the scope and result

Record the tested component, client, peer, protocol, selected algorithm, and date. Keep observed negotiation, documented capability, and unknown distinct. A failed check can reflect local tooling, certificate validation, network policy, or configuration; it does not prove that all PQC is unsupported.

Official references

Guidance reviewed 24 September 2026. Verify documentation for your deployed release; vendor capabilities and defaults change.