How the scan works
The scanner runs OpenSSL 3.5 or later, the first OpenSSL release with native ML-KEM support. For each domain it performs a series of ordinary TLS handshakes, never more than four at a time:
- Post-quantum key exchange. We offer each standardized post-quantum group alone (X25519MLKEM768, SecP256r1MLKEM768, SecP384r1MLKEM1024 and pure ML-KEM-512/768/1024). A group is reported as supported only if the server completes the handshake with it. We also record the group a modern browser would get when it offers both hybrid and classical options.
- Protocol versions. One handshake per version, from TLS 1.0 to TLS 1.3. For legacy versions the client accepts weak parameters, so that insecure configurations can be inventoried rather than missed.
- Cipher suites. For TLS 1.2 and below, we offer every suite, record the server's choice, remove it and repeat until the server refuses. For TLS 1.3, each of the five standard suites is tested individually.
- Certificates. The full chain is parsed: key type and size, curve, signature algorithm, validity and names. Each key is mapped to the algorithm catalog to state its quantum risk.
- HTTP. One request over HTTPS reads HSTS and CDN headers; one request over plain HTTP checks the redirect to HTTPS.
The catalog
Classifications come from a versioned catalog of algorithms, TLS groups and regulations. Every entry must cite at least one source; entries citing drafts, such as NIST IR 8547 and SP 800-131A Rev. 3, are labelled as drafts. The catalog is validated automatically: a position without a source, an unknown authority or a quantum-vulnerable algorithm without a post-quantum replacement blocks publication.
Limits you should know
- External view only. We see what the internet sees. Behind a CDN, results describe the CDN edge, not your origin server, and internal services are out of reach of a web scan.
- Point in time. A scan reflects the configuration at that moment; results are cached for one hour.
- Obsolete drafts. Pre-standard Kyber groups such as X25519Kyber768Draft00 are not tested: they are obsolete and should be replaced by ML-KEM.
- Not a certification. Results are facts about a configuration, useful to build an inventory. They are not an audit, a certification or legal advice.