← Knowledge base

Linux

Linux is not one TLS implementation. Distribution packages, application bundles, containers, and language runtimes may use different crypto libraries.

Evidence to collect

  1. Record the application’s package and crypto-library versions.
  2. Check inside the actual container or runtime; the host’s openssl command can be unrelated.
  3. Use the local checks with supported packages rather than replacing system libraries or loading experimental providers.
  4. Treat SSH, VPN, browser, mail, and application TLS as separate connections.

Read-only inventory

Run this in the environment used by the application. Missing commands mean the tool is unavailable. This output is inventory, not a negotiation result.

openssl version
ssh -V

Record the scope and result

Record the tested component, client, peer, protocol, selected algorithm, and date. Keep observed negotiation, documented capability, and unknown distinct. A failed check can reflect local tooling, certificate validation, network policy, or configuration; it does not prove that all PQC is unsupported.

Official references

Guidance reviewed 24 September 2026. Verify documentation for your deployed release; vendor capabilities and defaults change.