NOTES
External cryptography review should describe the security property that is weak: obsolete protocol negotiation, weak key exchange, deprecated signatures, small parameters, certificate problems, or insecure HTTP transport.
I consolidate related protocol issues by service when the remediation and impact are the same, but keep TLS and SSH findings separate because their configurations, clients, and fixes differ.
TLS
- Confirm the hostname and SNI value.
- Record supported protocol versions before cipher details.
- Review certificate chain, names, dates, signatures, and key sizes.
- Check negotiated ciphers, forward secrecy, known protocol vulnerabilities, redirects, and HSTS.
- Validate a scanner claim with a direct client connection when possible.
SSH
- Capture the banner and implementation version.
- Enumerate key exchange, host-key, encryption, and MAC algorithms.
- Distinguish deprecated algorithms from algorithms that are merely uncommon.
- Record parameter sizes and SHA-1 dependencies.
- Verify whether a safe client can still negotiate a strong combination.
COMMANDS
testssl.sh --warnings batch --color 0 HOST:PORT
ssh-audit HOST:PORT
openssl s_client -connect HOST:PORT -servername HOST -tls1_2
ssh -vv -oHostKeyAlgorithms=ALGORITHM USER@HOST
GOTCHAS
- Do not call a service vulnerable solely because its software banner is old.
- Protocol support and actual negotiation are different evidence.
- HSTS applies to browsers over HTTPS and should be evaluated with redirect behavior.
- Recommendations should preserve compatibility requirements while setting a clear retirement plan.