xutil.dev
Login

Cipher Suites

TLS 1.2/1.3 cipher suite reference with security recommendations. Review ECDHE, AES-GCM, ChaCha20, and other algorithm combinations for server TLS hardening and security audits

Related Categories:SSL/TLSSecurity
Protocol Version
Security Rating

32 entries

Cipher Suite NameProtocolKey Exch.AuthEncryptionMACRating
TLS_AES_256_GCM_SHA384TLS 1.3Any (ECDHE/DHE)AnyAES-256-GCMSHA-384Recommended
TLS_AES_128_GCM_SHA256TLS 1.3Any (ECDHE/DHE)AnyAES-128-GCMSHA-256Recommended
TLS_CHACHA20_POLY1305_SHA256TLS 1.3Any (ECDHE/DHE)AnyChaCha20-Poly1305SHA-256Recommended
TLS_AES_128_CCM_SHA256TLS 1.3Any (ECDHE/DHE)AnyAES-128-CCMSHA-256Recommended
TLS_AES_128_CCM_8_SHA256TLS 1.3Any (ECDHE/DHE)AnyAES-128-CCM-8SHA-256Recommended
TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384TLS 1.2ECDHEECDSAAES-256-GCMSHA-384Recommended
TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256TLS 1.2ECDHEECDSAAES-128-GCMSHA-256Recommended
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384TLS 1.2ECDHERSAAES-256-GCMSHA-384Recommended
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256TLS 1.2ECDHERSAAES-128-GCMSHA-256Recommended
TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256TLS 1.2ECDHEECDSAChaCha20-Poly1305SHA-256Recommended
TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256TLS 1.2ECDHERSAChaCha20-Poly1305SHA-256Recommended
TLS_DHE_RSA_WITH_AES_256_GCM_SHA384TLS 1.2DHERSAAES-256-GCMSHA-384Recommended
TLS_DHE_RSA_WITH_AES_128_GCM_SHA256TLS 1.2DHERSAAES-128-GCMSHA-256Recommended
TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384TLS 1.2ECDHEECDSAAES-256-CBCSHA-384Acceptable
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384TLS 1.2ECDHERSAAES-256-CBCSHA-384Acceptable
TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256TLS 1.2ECDHEECDSAAES-128-CBCSHA-256Acceptable
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256TLS 1.2ECDHERSAAES-128-CBCSHA-256Acceptable
TLS_DHE_RSA_WITH_AES_256_CBC_SHA256TLS 1.2DHERSAAES-256-CBCSHA-256Acceptable
TLS_DHE_RSA_WITH_AES_128_CBC_SHA256TLS 1.2DHERSAAES-128-CBCSHA-256Acceptable
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHATLS 1.2ECDHERSAAES-256-CBCSHA-1Weak
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHATLS 1.2ECDHERSAAES-128-CBCSHA-1Weak
TLS_RSA_WITH_AES_256_GCM_SHA384TLS 1.2RSARSAAES-256-GCMSHA-384Weak
TLS_RSA_WITH_AES_128_GCM_SHA256TLS 1.2RSARSAAES-128-GCMSHA-256Weak
TLS_RSA_WITH_AES_256_CBC_SHA256TLS 1.2RSARSAAES-256-CBCSHA-256Weak
TLS_RSA_WITH_AES_128_CBC_SHA256TLS 1.2RSARSAAES-128-CBCSHA-256Weak
TLS_RSA_WITH_AES_256_CBC_SHATLS 1.2RSARSAAES-256-CBCSHA-1Weak
TLS_RSA_WITH_AES_128_CBC_SHATLS 1.2RSARSAAES-128-CBCSHA-1Weak
TLS_RSA_WITH_3DES_EDE_CBC_SHATLS 1.2RSARSA3DES-EDE-CBCSHA-1Insecure
TLS_RSA_WITH_RC4_128_SHATLS 1.2RSARSARC4-128SHA-1Insecure
TLS_RSA_WITH_RC4_128_MD5TLS 1.2RSARSARC4-128MD5Insecure
TLS_RSA_WITH_NULL_SHA256TLS 1.2RSARSANULLSHA-256Insecure
TLS_RSA_WITH_NULL_SHATLS 1.2RSARSANULLSHA-1Insecure