TLS version monitoring
DoubleCheck connects to your server and records which TLS version it uses, so you see which servers are on TLS 1.3 and which still need work.
The problem
Which TLS versions a server offers depends on its software, its configuration and whatever sits in front of it. An update or a new load balancer can change it without anyone noticing.
Old servers and appliances are often still on TLS 1.2 or older, and nobody has a list.
Why it matters
TLS 1.0 and 1.1 are no longer considered safe and modern browsers no longer accept them. TLS 1.3 is faster to set up and drops the older, weaker options.
Security questionnaires and audits increasingly ask which TLS versions you support. A daily measurement is a better answer than a guess.
How to check it manually
Test whether the server accepts TLS 1.3, and then TLS 1.2, with openssl:
openssl s_client -connect www.example.com:443 -servername www.example.com -tls1_3 </dev/null
openssl s_client -connect www.example.com:443 -servername www.example.com -tls1_2 </dev/null
Or run an online TLS test against the host, one server at a time.
How DoubleCheck checks it
DoubleCheck makes a TLS connection the way a modern client does and records the version the server agrees to. TLS 1.3 is OK, TLS 1.2 gives a warning, so you know which servers to upgrade next.
Because it is checked continuously, you also notice when a server falls back to an older version after a change.
- Measures
- A TLS connection to your server (port 443 unless you set another), recording the TLS version the server agrees to use.
- Runs
- Every minute by default. You set the interval per check.
- Status
-
- OK when the server uses TLS 1.3.
- Warning when it uses TLS 1.2.
- Error when it only offers an older version, or the connection or certificate check fails.
Frequently asked questions
Why is TLS 1.2 a warning and not OK?
TLS 1.2 is still safe when configured well, but TLS 1.3 is the current version. The warning keeps the servers that can be upgraded visible.
Which port is checked?
Port 443 unless you set another port, so you can check mail servers or other TLS services as well.
Does this check the certificate too?
The connection fails, and the check goes to error, if the certificate is not trusted or does not match the host name. For the expiry date there is a separate certificate expiry check.
Start monitoring with DoubleCheck
Alerts by email, SMS, Slack, Microsoft Teams or Discord. You pay per check run: cost management in the app shows what every check costs, and a longer interval lowers it.