TLS Cipher Suites
A reference of the TLS cipher suites you will encounter in a real scan, with their hex IDs, protocol version, encryption algorithm, key size, whether they provide forward secrecy, and a direct assessment of whether to keep or disable each one.
| Cipher suite | ID | Protocol | Encryption | Bits | Forward secrecy | Assessment |
|---|---|---|---|---|---|---|
| TLS_AES_128_GCM_SHA256 | 0x1301 | TLS 1.3 | AES-128-GCM | 128 | Yes | Recommended |
| TLS_AES_256_GCM_SHA384 | 0x1302 | TLS 1.3 | AES-256-GCM | 256 | Yes | Recommended |
| TLS_CHACHA20_POLY1305_SHA256 | 0x1303 | TLS 1.3 | ChaCha20-Poly1305 | 256 | Yes | Recommended |
| ECDHE-ECDSA-AES128-GCM-SHA256 | 0xc02b | TLS 1.2 | AES-128-GCM | 128 | Yes | Recommended |
| ECDHE-ECDSA-AES256-GCM-SHA384 | 0xc02c | TLS 1.2 | AES-256-GCM | 256 | Yes | Recommended |
| ECDHE-RSA-AES128-GCM-SHA256 | 0xc02f | TLS 1.2 | AES-128-GCM | 128 | Yes | Recommended |
| ECDHE-RSA-AES256-GCM-SHA384 | 0xc030 | TLS 1.2 | AES-256-GCM | 256 | Yes | Recommended |
| ECDHE-ECDSA-CHACHA20-POLY1305 | 0xcca9 | TLS 1.2 | ChaCha20-Poly1305 | 256 | Yes | Recommended |
| ECDHE-RSA-CHACHA20-POLY1305 | 0xcca8 | TLS 1.2 | ChaCha20-Poly1305 | 256 | Yes | Recommended |
| DHE-RSA-AES128-GCM-SHA256 | 0x009e | TLS 1.2 | AES-128-GCM | 128 | Yes | Acceptable |
| DHE-RSA-AES256-GCM-SHA384 | 0x009f | TLS 1.2 | AES-256-GCM | 256 | Yes | Acceptable |
| ECDHE-RSA-AES128-SHA256 | 0xc027 | TLS 1.2 | AES-128-CBC | 128 | Yes | Weak — CBC mode |
| ECDHE-RSA-AES256-SHA384 | 0xc028 | TLS 1.2 | AES-256-CBC | 256 | Yes | Weak — CBC mode |
| ECDHE-RSA-AES128-SHA | 0xc013 | TLS 1.0+ | AES-128-CBC | 128 | Yes | Weak — SHA-1 MAC |
| ECDHE-RSA-AES256-SHA | 0xc014 | TLS 1.0+ | AES-256-CBC | 256 | Yes | Weak — SHA-1 MAC |
| AES128-GCM-SHA256 | 0x009c | TLS 1.2 | AES-128-GCM | 128 | No | Weak — no forward secrecy |
| AES256-GCM-SHA384 | 0x009d | TLS 1.2 | AES-256-GCM | 256 | No | Weak — no forward secrecy |
| AES128-SHA | 0x002f | TLS 1.0+ | AES-128-CBC | 128 | No | Weak — no forward secrecy, SHA-1 |
| AES256-SHA | 0x0035 | TLS 1.0+ | AES-256-CBC | 256 | No | Weak — no forward secrecy, SHA-1 |
| DES-CBC3-SHA | 0x000a | TLS 1.0+ | 3DES-CBC | 112 | No | Insecure — SWEET32, disable |
| RC4-SHA | 0x0005 | TLS 1.0+ | RC4-128 | 128 | No | Insecure — RC4 is broken, disable |
| RC4-MD5 | 0x0004 | TLS 1.0+ | RC4-128 | 128 | No | Insecure — RC4 and MD5, disable |
| NULL-SHA | 0x0002 | SSL 3.0+ | None | 0 | No | Insecure — no encryption at all |
About this reference
A reference of the TLS cipher suites you will encounter in a real scan, with their hex IDs, protocol version, encryption algorithm, key size, whether they provide forward secrecy, and a direct assessment of whether to keep or disable each one.
This page is static data served straight from the edge, so it loads instantly and works without JavaScript. Filtering happens in your browser — nothing you type is sent anywhere.