How to read TLS versions and cipher suites
A TLS scan reports the protocol and cipher selected for the connection that was tested. That result is not necessarily the complete list of options a server supports. A client’s capabilities, server policy, and negotiation preferences influence the selection.
Certificate algorithm versus cipher suite
The certificate signature and public key identify certificate material. The negotiated cipher suite describes parts of the session’s protection. These are related to the same connection but are not interchangeable facts. In TLS 1.3, the cipher-suite name does not identify the key-exchange group or certificate authentication method.
What to investigate
- Prefer current TLS versions supported by the organization’s clients.
- Remove legacy protocols and suites only after checking compatibility and exception requirements.
- Record the actual negotiated result separately from the configured supported list.
- Review key exchange, authentication, and certificate algorithms as separate controls.
- Test through every public listener and proxy path that matters to users.
Certificate Inspector reports the negotiated version and cipher returned by its scanner. It does not claim that one connection proves every supported cipher or every client outcome. For post-quantum work, the scanner reports when the key-exchange group is not observable rather than inferring ML-KEM from a TLS version or cipher name.
Last reviewed: September 2026.