How to read TLS versions and cipher suites

A TLS scan reports the protocol and cipher selected for the connection that was tested. That result is not necessarily the complete list of options a server supports. A client’s capabilities, server policy, and negotiation preferences influence the selection.

Certificate algorithm versus cipher suite

The certificate signature and public key identify certificate material. The negotiated cipher suite describes parts of the session’s protection. These are related to the same connection but are not interchangeable facts. In TLS 1.3, the cipher-suite name does not identify the key-exchange group or certificate authentication method.

What to investigate

Certificate Inspector reports the negotiated version and cipher returned by its scanner. It does not claim that one connection proves every supported cipher or every client outcome. For post-quantum work, the scanner reports when the key-exchange group is not observable rather than inferring ML-KEM from a TLS version or cipher name.

Last reviewed: September 2026.