Security · TLS

TLS cipher suite checker.

Paste cipher suite names (OpenSSL or IANA) or hex codes, from openssl ciphers, a server config or a packet capture, and get each suite’s IANA registry entry: value, DTLS-OK, Recommended and reference RFC. Suites that are TLS 1.3-only, CBC, RC4, 3DES, NULL, EXPORT or anonymous are flagged by name. Everything runs in your browser; nothing is sent and no server is contacted.

Source: IANA TLS Cipher Suites registry, last updated 2026-09-18 (snapshot fetched 2026-10-01) IANA “Recommended” is not a security audit of your server

Advertisement

Cipher suites

One per line, or separated by spaces, commas, semicolons or colons. Accepted: OpenSSL names (ECDHE-RSA-AES128-GCM-SHA256), IANA names (TLS_RSA_WITH_AES_128_CBC_SHA) and hex (0xC0,0x2F, 0xC02F or C02F). OpenSSL keywords such as HIGH or !aNULL are listed as not matched.

Registry lookup

Paste cipher suites and press Check suites.

Worked example

Pasting ECDHE-RSA-AES128-GCM-SHA256 resolves to IANA TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256, value 0xC0,0x2F, DTLS-OK Y, Recommended Y, reference RFC 5289. Pasting AES128-SHA resolves to TLS_RSA_WITH_AES_128_CBC_SHA, 0x00,0x2F, Recommended D (discouraged), and is flagged for CBC mode, a SHA-1 MAC and static RSA key exchange (no forward secrecy). Use “Load example” to see a mixed list.

How the flags are decided

Flags come only from the underscore-separated tokens of the IANA suite name, so they are a reading of the name, not a test of anything. TLS 1.3 style: the name has no _WITH_ part (for example TLS_AES_256_GCM_SHA384); IANA notes these cannot be used for TLS 1.2 or lower and the reverse. NULL, EXPORT, anon, RC4, 3DES, single DES, RC2, IDEA and MD5 are marked weak. CBC, a trailing SHA (HMAC-SHA1) and static key exchange (TLS_RSA_WITH_, or static DH/ECDH) are marked legacy. DHE/ECDHE and TLS 1.3 names get a forward-secrecy note. Reserved GREASE values (RFC 8701) and the SCSV signalling values are labelled as such. Entries IANA lists as Unassigned or Reserved for Private Use are not in the snapshot and show as not matched.

Reading the IANA columns

DTLS-OK says whether the suite is usable with DTLS. Recommended is Y, N or D. Per the registry notes, N “does not necessarily mean” flawed: the suite may not have gone through the IETF consensus process, may have limited applicability, or may be for specific use cases. D means discouraged: it SHOULD NOT or MUST NOT be used, depending on the situation, so check the referenced RFC. CCM_8 suites are intentionally not marked Recommended. The registry itself warns that cryptographic algorithms and parameters weaken over time and that implementers should not blindly implement listed suites.

Frequently asked questions

Does Recommended = Y mean my server is secure?

No. It is a property of one registry entry. It says nothing about which suites your server offers, their order, protocol versions, certificates, key sizes, session handling or software patch level.

Where do the OpenSSL names come from?

They are the names printed by openssl ciphers -V 'ALL:COMPLEMENTOFALL:@SECLEVEL=0' on OpenSSL 3.6.4, joined to IANA rows by the two-byte value (see the OpenSSL ciphers manual). Suites OpenSSL does not implement can only be looked up by IANA name or hex. Other libraries (GnuTLS, NSS, Java) use their own names; paste the IANA name or hex for those.

Why is a suite I use not found?

Either it is spelled differently, it is a cipher-string keyword (HIGH, ALL, !aNULL), or it is not in the snapshot. Newer registry additions after 2026-09-18 are missing; check the live IANA table.

Can this test a live server?

No. It never connects to anything. To see what a server offers, run a scanner you control against it, then paste the suite list here to decode it.

Sources: IANA, TLS Cipher Suites registry (CSV tls-parameters-4.csv; registry last updated 2026-09-18; snapshot fetched 2026-10-01); RFC 8701 (GREASE); RFC 7465 (prohibiting RC4); OpenSSL ciphers manual.

What this check does and doesn’t tell you

This tool looks up pasted suites in a static copy of the IANA registry and reads the suite names. IANA “Recommended” is not a security audit of a server: it does not test configuration, protocol versions, certificates or patching. Registry values change, so confirm against the live IANA table before relying on a result. Nothing is fetched, stored or transmitted.

Advertisement
Advertisement
Listening…