Endpoint check

TLS version monitoring

DoubleCheck connects to your server and records which TLS version it uses, so you see which servers are on TLS 1.3 and which still need work.

The problem

Which TLS versions a server offers depends on its software, its configuration and whatever sits in front of it. An update or a new load balancer can change it without anyone noticing.

Old servers and appliances are often still on TLS 1.2 or older, and nobody has a list.

Why it matters

TLS 1.0 and 1.1 are no longer considered safe and modern browsers no longer accept them. TLS 1.3 is faster to set up and drops the older, weaker options.

Security questionnaires and audits increasingly ask which TLS versions you support. A daily measurement is a better answer than a guess.

How to check it manually

Test whether the server accepts TLS 1.3, and then TLS 1.2, with openssl:

openssl s_client -connect www.example.com:443 -servername www.example.com -tls1_3 </dev/null
openssl s_client -connect www.example.com:443 -servername www.example.com -tls1_2 </dev/null

Or run an online TLS test against the host, one server at a time.

How DoubleCheck checks it

DoubleCheck makes a TLS connection the way a modern client does and records the version the server agrees to. TLS 1.3 is OK, TLS 1.2 gives a warning, so you know which servers to upgrade next.

Because it is checked continuously, you also notice when a server falls back to an older version after a change.

Measures
A TLS connection to your server (port 443 unless you set another), recording the TLS version the server agrees to use.
Runs
Every minute by default. You set the interval per check.
Status
  • OK when the server uses TLS 1.3.
  • Warning when it uses TLS 1.2.
  • Error when it only offers an older version, or the connection or certificate check fails.
FAQ

Frequently asked questions

Why is TLS 1.2 a warning and not OK?

TLS 1.2 is still safe when configured well, but TLS 1.3 is the current version. The warning keeps the servers that can be upgraded visible.

Which port is checked?

Port 443 unless you set another port, so you can check mail servers or other TLS services as well.

Does this check the certificate too?

The connection fails, and the check goes to error, if the certificate is not trusted or does not match the host name. For the expiry date there is a separate certificate expiry check.

Get started

Start monitoring with DoubleCheck

Alerts by email, SMS, Slack, Microsoft Teams or Discord. You pay per check run: cost management in the app shows what every check costs, and a longer interval lowers it.

Start monitoring