Linux
Linux is not one TLS implementation. Distribution packages, application bundles, containers, and language runtimes may use different crypto libraries.
Evidence to collect
- Record the application’s package and crypto-library versions.
- Check inside the actual container or runtime; the host’s openssl command can be unrelated.
- Use the local checks with supported packages rather than replacing system libraries or loading experimental providers.
- Treat SSH, VPN, browser, mail, and application TLS as separate connections.
Read-only inventory
Run this in the environment used by the application. Missing commands mean the tool is unavailable. This output is inventory, not a negotiation result.
openssl version
ssh -VRecord the scope and result
Record the tested component, client, peer, protocol, selected algorithm, and date. Keep observed negotiation, documented capability, and unknown distinct. A failed check can reflect local tooling, certificate validation, network policy, or configuration; it does not prove that all PQC is unsupported.
Official references
Guidance reviewed 24 September 2026. Verify documentation for your deployed release; vendor capabilities and defaults change.