← Knowledge base

PHP

PHP OpenSSL streams and PHP cURL can use different TLS integrations. The web server terminating inbound HTTPS is another independent component.

Evidence to collect

  1. Record the PHP runtime and OpenSSL extension build.
  2. If the application uses cURL, inspect its TLS backend separately.
  3. Test outbound application requests independently of inbound web-server TLS; avoid using phpinfo() on a public page to expose environment details.

Read-only inventory

Run this in the environment used by the application. Missing commands mean the tool is unavailable. This output is inventory, not a negotiation result.

php -r 'echo defined("OPENSSL_VERSION_TEXT") ? OPENSSL_VERSION_TEXT : "OpenSSL extension unavailable"; echo PHP_EOL;'

Record the scope and result

Record the tested component, client, peer, protocol, selected algorithm, and date. Keep observed negotiation, documented capability, and unknown distinct. A failed check can reflect local tooling, certificate validation, network policy, or configuration; it does not prove that all PQC is unsupported.

Official references

Guidance reviewed 24 September 2026. Verify documentation for your deployed release; vendor capabilities and defaults change.