Python
Python’s ssl module wraps OpenSSL. Different Python distributions can link or bundle different OpenSSL releases, independently of the executable on your PATH.
Evidence to collect
- Inspect ssl.OPENSSL_VERSION using the interpreter that runs the application.
- Check the actual HTTP library, proxy path, SSL context, and trust configuration.
- SSLSocket.cipher() reports the cipher suite, not the selected key-exchange group. Treat a missing group as unknown.
- A local OpenSSL check establishes server capability with that tool; it does not certify requests made by Python.
Read-only inventory
Run this in the environment used by the application. Missing commands mean the tool is unavailable. This output is inventory, not a negotiation result.
python3 -c "import ssl; print(ssl.OPENSSL_VERSION)"Record the scope and result
Record the tested component, client, peer, protocol, selected algorithm, and date. Keep observed negotiation, documented capability, and unknown distinct. A failed check can reflect local tooling, certificate validation, network policy, or configuration; it does not prove that all PQC is unsupported.
Official references
Guidance reviewed 24 September 2026. Verify documentation for your deployed release; vendor capabilities and defaults change.