PHP
PHP OpenSSL streams and PHP cURL can use different TLS integrations. The web server terminating inbound HTTPS is another independent component.
Evidence to collect
- Record the PHP runtime and OpenSSL extension build.
- If the application uses cURL, inspect its TLS backend separately.
- Test outbound application requests independently of inbound web-server TLS; avoid using phpinfo() on a public page to expose environment details.
Read-only inventory
Run this in the environment used by the application. Missing commands mean the tool is unavailable. This output is inventory, not a negotiation result.
php -r 'echo defined("OPENSSL_VERSION_TEXT") ? OPENSSL_VERSION_TEXT : "OpenSSL extension unavailable"; echo PHP_EOL;'Record the scope and result
Record the tested component, client, peer, protocol, selected algorithm, and date. Keep observed negotiation, documented capability, and unknown distinct. A failed check can reflect local tooling, certificate validation, network policy, or configuration; it does not prove that all PQC is unsupported.
Official references
Guidance reviewed 24 September 2026. Verify documentation for your deployed release; vendor capabilities and defaults change.