TLS Cipher Suites

A reference of the TLS cipher suites you will encounter in a real scan, with their hex IDs, protocol version, encryption algorithm, key size, whether they provide forward secrecy, and a direct assessment of whether to keep or disable each one.

23 entries

Cipher suiteIDProtocolEncryptionBitsForward secrecyAssessment
TLS_AES_128_GCM_SHA2560x1301TLS 1.3AES-128-GCM128YesRecommended
TLS_AES_256_GCM_SHA3840x1302TLS 1.3AES-256-GCM256YesRecommended
TLS_CHACHA20_POLY1305_SHA2560x1303TLS 1.3ChaCha20-Poly1305256YesRecommended
ECDHE-ECDSA-AES128-GCM-SHA2560xc02bTLS 1.2AES-128-GCM128YesRecommended
ECDHE-ECDSA-AES256-GCM-SHA3840xc02cTLS 1.2AES-256-GCM256YesRecommended
ECDHE-RSA-AES128-GCM-SHA2560xc02fTLS 1.2AES-128-GCM128YesRecommended
ECDHE-RSA-AES256-GCM-SHA3840xc030TLS 1.2AES-256-GCM256YesRecommended
ECDHE-ECDSA-CHACHA20-POLY13050xcca9TLS 1.2ChaCha20-Poly1305256YesRecommended
ECDHE-RSA-CHACHA20-POLY13050xcca8TLS 1.2ChaCha20-Poly1305256YesRecommended
DHE-RSA-AES128-GCM-SHA2560x009eTLS 1.2AES-128-GCM128YesAcceptable
DHE-RSA-AES256-GCM-SHA3840x009fTLS 1.2AES-256-GCM256YesAcceptable
ECDHE-RSA-AES128-SHA2560xc027TLS 1.2AES-128-CBC128YesWeak — CBC mode
ECDHE-RSA-AES256-SHA3840xc028TLS 1.2AES-256-CBC256YesWeak — CBC mode
ECDHE-RSA-AES128-SHA0xc013TLS 1.0+AES-128-CBC128YesWeak — SHA-1 MAC
ECDHE-RSA-AES256-SHA0xc014TLS 1.0+AES-256-CBC256YesWeak — SHA-1 MAC
AES128-GCM-SHA2560x009cTLS 1.2AES-128-GCM128NoWeak — no forward secrecy
AES256-GCM-SHA3840x009dTLS 1.2AES-256-GCM256NoWeak — no forward secrecy
AES128-SHA0x002fTLS 1.0+AES-128-CBC128NoWeak — no forward secrecy, SHA-1
AES256-SHA0x0035TLS 1.0+AES-256-CBC256NoWeak — no forward secrecy, SHA-1
DES-CBC3-SHA0x000aTLS 1.0+3DES-CBC112NoInsecure — SWEET32, disable
RC4-SHA0x0005TLS 1.0+RC4-128128NoInsecure — RC4 is broken, disable
RC4-MD50x0004TLS 1.0+RC4-128128NoInsecure — RC4 and MD5, disable
NULL-SHA0x0002SSL 3.0+None0NoInsecure — no encryption at all

About this reference

A reference of the TLS cipher suites you will encounter in a real scan, with their hex IDs, protocol version, encryption algorithm, key size, whether they provide forward secrecy, and a direct assessment of whether to keep or disable each one.

This page is static data served straight from the edge, so it loads instantly and works without JavaScript. Filtering happens in your browser — nothing you type is sent anywhere.