A worked example, rendered from real sample data. Sign in to run the tool on your own input.
TLS_AES_128_GCM_SHA256
ECDHE-ECDSA-AES256-GCM-SHA384
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
AES128-SHA
DES-CBC3-SHA═══ Summary ═══
Suites analysed: 5
Forward secrecy: 3 of 5
AEAD: 3 of 5
Profile: intermediate (keeps grade A and B)
Grades: A+×1 A×2 D×2
✗ 2 suites fall below the intermediate profile and should be removed.
═══ TLS_AES_128_GCM_SHA256 — grade A+ ═══
IANA name: TLS_AES_128_GCM_SHA256
OpenSSL name: TLS_AES_128_GCM_SHA256
Key exchange: TLS 1.3 — TLS 1.3 always negotiates an ephemeral (EC)DHE group separately from the cipher suite
Authentication: TLS 1.3 — the certificate and signature algorithm are negotiated separately from the cipher suite
Bulk cipher: AES128 (128-bit key)
Mode: GCM — AEAD — encryption and integrity in one pass, no separate MAC, immune to the padding-oracle family
MAC / PRF: SHA256 (hash used for the key schedule; integrity comes from the AEAD tag)
TLS versions: TLS 1.3 only
✓ Forward secrecy — each session gets a fresh ephemeral key.
✓ AEAD — encryption and integrity in a single construction.
✓ TLS 1.3 suite: forward secrecy and AEAD are mandatory, and the key exchange is negotiated separately.
═══ ECDHE-ECDSA-AES256-GCM-SHA384 — grade A ═══
IANA name: TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
OpenSSL name: ECDHE-ECDSA-AES256-GCM-SHA384
Key exchange: ECDHE — ephemeral elliptic-curve Diffie-Hellman — a fresh key per connection, so past traffic stays safe if the server key leaks
Authentication: ECDSA — an ECDSA certificate signs the handshake — smaller and faster than RSA at the same strength
Bulk cipher: AES256 (256-bit key)
Mode: GCM — AEAD — encryption and integrity in one pass, no separate MAC, immune to the padding-oracle family
MAC / PRF: SHA384 (hash
…
Grade cipher suites in either spelling and emit a config with the weak ones removed. Part of the DevTools Surf developer suite. Browse more tools in the Security / Crypto collection.