↑ ↓ select, Enter open, Esc close

Check whether a server supports TLS 1.3

Adjust the values, the command updates live
user@server
openssl s_client -connect example.com:443 -servername example.com -tls1_3 </dev/null 2>/dev/null | grep -E "^New,|Protocol *:"

Connects using TLS 1.3 only and prints the negotiated protocol and cipher suite, such as TLSv1.3 with TLS_AES_256_GCM_SHA384. If the output is empty or shows Cipher is (NONE), the server does not speak TLS 1.3. Use -tls1_2 to test the older version the same way.

Note: Outdated protocols like TLS 1.0 cannot be tested reliably this way, because the local OpenSSL often no longer offers them itself.

Also searched as

  • check if tls 1.3 is enabled
  • which tls versions does a server support
  • test tls protocol openssl

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.