← Knowledge base

macOS

macOS applications may use Apple networking frameworks or bundled crypto libraries. A standalone OpenSSL result belongs to that tool, not automatically to Safari or other apps.

Evidence to collect

  1. Record the OS and application versions.
  2. Use the browser check for the browser connection; use local TLS instructions for a specific endpoint.
  3. Identify the backend used by each application, including containers and runtimes.

Read-only inventory

Run this in the environment used by the application. Missing commands mean the tool is unavailable. This output is inventory, not a negotiation result.

sw_vers

Record the scope and result

Record the tested component, client, peer, protocol, selected algorithm, and date. Keep observed negotiation, documented capability, and unknown distinct. A failed check can reflect local tooling, certificate validation, network policy, or configuration; it does not prove that all PQC is unsupported.

Official references

Guidance reviewed 24 September 2026. Verify documentation for your deployed release; vendor capabilities and defaults change.