---
title: TLSCipherSuite enum | Wartiva GraphQL API
description: SSL (Secure Sockets Layer) and TLS (Transport Layer Security) Cipher Suites enum in IANA format see OpenSSL to IANA cipher suite mapping.
url: https://wartiva.com/api-docs/types/tls-cipher-suite.html
updated: 2026-10-07
---

Networks, devices, and sensors · GraphQL enum

# `TLSCipherSuite` enum

SSL (Secure Sockets Layer) and TLS (Transport Layer Security) Cipher Suites enum in IANA format see [OpenSSL to IANA cipher suite mapping](https://testssl.sh/openssl-iana.mapping.html).

## Values

| Enum Value | Description |
|---|---|
| `TLS_RSA_WITH_RC4_128_SHA` | Rivest Shamir Adleman algorithm (RSA) see [RFC 5246 — TLS Protocol Version 1.2](https://datatracker.ietf.org/doc/html/rfc5246). Conclusion: INSECURE. Non-ephemeral Key Exchange: This key exchange algorithm does not support Perfect Forward Secrecy (PFS) which is recommended, so attackers cannot decrypt the complete communication stream. Rivest Cipher 4: IETF has officially prohibited RC4 for use in TLS in RFC 7465. Therefore, it can be considered insecure. Secure Hash Algorithm 1: The Secure Hash Algorithm 1 has been proven to be insecure as of 2017 (see shattered.io). |
| `TLS_RSA_WITH_3DES_EDE_CBC_SHA` | Rivest Shamir Adleman algorithm (RSA) see [RFC 5246 — TLS Protocol Version 1.2](https://datatracker.ietf.org/doc/html/rfc5246). Conclusion: WEAK. This key exchange algorithm does not support Perfect Forward Secrecy (PFS) which is recommended, so attackers cannot decrypt the complete communication stream. Cipher Block Chaining: In 2013, researchers demonstrated a timing attack against several TLS implementations using the CBC encryption algorithm (see isg.rhul.ac.uk). Additionally, the CBC mode is vulnerable to plain-text attacks in TLS 1.0, SSL 3.0 and lower. A fix has been introduced with TLS 1.2 in form of the GCM mode which is not vulnerable to the BEAST attack. GCM should be preferred over CBC. Triple-DES: While Triple-DES is still recognized as a secure symmetric-key encryption, a more and more standardizations bodies and projects decide to deprecate this algorithm. Though not broken, it has been proven to suffer from several vulnerabilities in the past (see sweet32.info). Secure Hash Algorithm 1: The Secure Hash Algorithm 1 has been proven to be insecure as of 2017 (see shattered.io). |
| `TLS_RSA_WITH_AES_128_CBC_SHA` | Rivest Shamir Adleman algorithm (RSA) see [RFC 5246 — TLS Protocol Version 1.2](https://datatracker.ietf.org/doc/html/rfc5246). Conclusion: WEAK. Non-ephemeral Key Exchange: This key exchange algorithm does not support Perfect Forward Secrecy (PFS) which is recommended, so attackers cannot decrypt the complete communication stream. Cipher Block Chaining: In 2013, researchers demonstrated a timing attack against several TLS implementations using the CBC encryption algorithm (see isg.rhul.ac.uk). Additionally, the CBC mode is vulnerable to plain-text attacks in TLS 1.0, SSL 3.0 and lower. A fix has been introduced with TLS 1.2 in form of the GCM mode which is not vulnerable to the BEAST attack. GCM should be preferred over CBC. Secure Hash Algorithm 1: The Secure Hash Algorithm 1 has been proven to be insecure as of 2017 (see shattered.io). |
| `TLS_RSA_WITH_AES_256_CBC_SHA` | Rivest Shamir Adleman algorithm (RSA) see [RFC 5246 — TLS Protocol Version 1.2](https://datatracker.ietf.org/doc/html/rfc5246). Conclusion: WEAK. Non-ephemeral Key Exchange: This key exchange algorithm does not support Perfect Forward Secrecy (PFS) which is recommended, so attackers cannot decrypt the complete communication stream. Cipher Block Chaining: In 2013, researchers demonstrated a timing attack against several TLS implementations using the CBC encryption algorithm (see isg.rhul.ac.uk). Additionally, the CBC mode is vulnerable to plain-text attacks in TLS 1.0, SSL 3.0 and lower. A fix has been introduced with TLS 1.2 in form of the GCM mode which is not vulnerable to the BEAST attack. GCM should be preferred over CBC. Secure Hash Algorithm 1: The Secure Hash Algorithm 1 has been proven to be insecure as of 2017 (see shattered.io). |
| `TLS_RSA_WITH_AES_128_CBC_SHA256` | Rivest Shamir Adleman algorithm (RSA) see [RFC 5246 — TLS Protocol Version 1.2](https://datatracker.ietf.org/doc/html/rfc5246). Conclusion: WEAK. Non-ephemeral Key Exchange: This key exchange algorithm does not support Perfect Forward Secrecy (PFS) which is recommended, so attackers cannot decrypt the complete communication stream. Cipher Block Chaining: In 2013, researchers demonstrated a timing attack against several TLS implementations using the CBC encryption algorithm (see isg.rhul.ac.uk). Additionally, the CBC mode is vulnerable to plain-text attacks in TLS 1.0, SSL 3.0 and lower. A fix has been introduced with TLS 1.2 in form of the GCM mode which is not vulnerable to the BEAST attack. GCM should be preferred over CBC. |
| `TLS_RSA_WITH_AES_128_GCM_SHA256` | Rivest Shamir Adleman algorithm (RSA) see [RFC 5246 — TLS Protocol Version 1.2](https://datatracker.ietf.org/doc/html/rfc5246). Conclusion: WEAK. Non-ephemeral Key Exchange: This key exchange algorithm does not support Perfect Forward Secrecy (PFS) which is recommended, so attackers cannot decrypt the complete communication stream. |
| `TLS_RSA_WITH_AES_256_GCM_SHA384` | Rivest Shamir Adleman algorithm (RSA) see [RFC 5246 — TLS Protocol Version 1.2](https://datatracker.ietf.org/doc/html/rfc5246). Conclusion: WEAK. Non-ephemeral Key Exchange: This key exchange algorithm does not support Perfect Forward Secrecy (PFS) which is recommended, so attackers cannot decrypt the complete communication stream. |
| `TLS_ECDHE_ECDSA_WITH_RC4_128_SHA` | Rivest Cipher 4 with 128bit key (RC4 128) see [RFC 8422 — ECC Cipher Suites for TLS](https://tools.ietf.org/html/rfc8422). Conclusion: INSECURE. Rivest Cipher 4: IETF has officially prohibited RC4 for use in TLS in RFC 7465. Therefore, it can be considered insecure. Secure Hash Algorithm 1: The Secure Hash Algorithm 1 has been proven to be insecure as of 2017 (see shattered.io). |
| `TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA` | Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) for Transport Layer Security (TLS) Versions 1.2 and Earlier see: [RFC 8422 — ECC Cipher Suites for TLS](https://tools.ietf.org/html/rfc8422). Conclusion: WEAK. Cipher Block Chaining: In 2013, researchers demonstrated a timing attack against several TLS implementations using the CBC encryption algorithm (see isg.rhul.ac.uk). Additionally, the CBC mode is vulnerable to plain-text attacks in TLS 1.0, SSL 3.0 and lower. A fix has been introduced with TLS 1.2 in form of the GCM mode which is not vulnerable to the BEAST attack. GCM should be preferred over CBC. Secure Hash Algorithm 1: The Secure Hash Algorithm 1 has been proven to be insecure as of 2017 (see shattered.io). |
| `TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA` | Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) see [RFC 8422 — ECC Cipher Suites for TLS](https://tools.ietf.org/html/rfc8422). Conclusion: WEAK. Cipher Block Chaining: In 2013, researchers demonstrated a timing attack against several TLS implementations using the CBC encryption algorithm (see isg.rhul.ac.uk). Additionally, the CBC mode is vulnerable to plain-text attacks in TLS 1.0, SSL 3.0 and lower. A fix has been introduced with TLS 1.2 in form of the GCM mode which is not vulnerable to the BEAST attack. GCM should be preferred over CBC. Secure Hash Algorithm 1: The Secure Hash Algorithm 1 has been proven to be insecure as of 2017 (see shattered.io). |
| `TLS_ECDHE_RSA_WITH_RC4_128_SHA` | Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) for Transport Layer Security (TLS) Versions 1.2 and Earlier see: [RFC 8422 — ECC Cipher Suites for TLS](https://tools.ietf.org/html/rfc8422). Conclusion: INSECURE. Rivest Cipher 4: IETF has officially prohibited RC4 for use in TLS in RFC 7465. Therefore, it can be considered insecure. Secure Hash Algorithm 1: The Secure Hash Algorithm 1 has been proven to be insecure as of 2017 (see shattered.io). |
| `TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA` | Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) for Transport Layer Security (TLS) Versions 1.2 and Earlier see: [RFC 8422 — ECC Cipher Suites for TLS](https://tools.ietf.org/html/rfc8422). Conclusion: WEAK. Cipher Block Chaining: In 2013, researchers demonstrated a timing attack against several TLS implementations using the CBC encryption algorithm (see isg.rhul.ac.uk). Additionally, the CBC mode is vulnerable to plain-text attacks in TLS 1.0, SSL 3.0 and lower. A fix has been introduced with TLS 1.2 in form of the GCM mode which is not vulnerable to the BEAST attack. GCM should be preferred over CBC. Triple-DES: While Triple-DES is still recognized as a secure symmetric-key encryption, a more and more standardizations bodies and projects decide to deprecate this algorithm. Though not broken, it has been proven to suffer from several vulnerabilities in the past (see sweet32.info). Secure Hash Algorithm 1: The Secure Hash Algorithm 1 has been proven to be insecure as of 2017 (see shattered.io). |
| `TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA` | Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) for Transport Layer Security (TLS) Versions 1.2 and Earlier see: [RFC 8422 — ECC Cipher Suites for TLS](https://tools.ietf.org/html/rfc8422). Conclusion: WEAK. Cipher Block Chaining: In 2013, researchers demonstrated a timing attack against several TLS implementations using the CBC encryption algorithm (see isg.rhul.ac.uk). Additionally, the CBC mode is vulnerable to plain-text attacks in TLS 1.0, SSL 3.0 and lower. A fix has been introduced with TLS 1.2 in form of the GCM mode which is not vulnerable to the BEAST attack. GCM should be preferred over CBC. Secure Hash Algorithm 1: The Secure Hash Algorithm 1 has been proven to be insecure as of 2017 (see shattered.io). |
| `TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA` | Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) for Transport Layer Security (TLS) Versions 1.2 and Earlier see: [RFC 8422 — ECC Cipher Suites for TLS](https://tools.ietf.org/html/rfc8422). Conclusion: WEAK. Cipher Block Chaining: In 2013, researchers demonstrated a timing attack against several TLS implementations using the CBC encryption algorithm (see isg.rhul.ac.uk). Additionally, the CBC mode is vulnerable to plain-text attacks in TLS 1.0, SSL 3.0 and lower. A fix has been introduced with TLS 1.2 in form of the GCM mode which is not vulnerable to the BEAST attack. GCM should be preferred over CBC. Secure Hash Algorithm 1: The Secure Hash Algorithm 1 has been proven to be insecure as of 2017 (see shattered.io). |
| `TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256` | Transport Layer Security (TLS) Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) see: [RFC 5289 — TLS Elliptic Curve Cipher Suites with SHA-256/384](https://datatracker.ietf.org/doc/html/rfc5289) Conclusion: WEAK. Cipher Block Chaining: In 2013, researchers demonstrated a timing attack against several TLS implementations using the CBC encryption algorithm (see isg.rhul.ac.uk). Additionally, the CBC mode is vulnerable to plain-text attacks in TLS 1.0, SSL 3.0 and lower. A fix has been introduced with TLS 1.2 in form of the GCM mode which is not vulnerable to the BEAST attack. GCM should be preferred over CBC. |
| `TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256` | Transport Layer Security (TLS) Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) see: [RFC 5289 — TLS Elliptic Curve Cipher Suites with SHA-256/384](https://datatracker.ietf.org/doc/html/rfc5289) Conclusion: WEAK. Cipher Block Chaining: In 2013, researchers demonstrated a timing attack against several TLS implementations using the CBC encryption algorithm (see isg.rhul.ac.uk). Additionally, the CBC mode is vulnerable to plain-text attacks in TLS 1.0, SSL 3.0 and lower. A fix has been introduced with TLS 1.2 in form of the GCM mode which is not vulnerable to the BEAST attack. GCM should be preferred over CBC. |
| `TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256` | Transport Layer Security (TLS) Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) see: [RFC 5289 — TLS Elliptic Curve Cipher Suites with SHA-256/384](https://datatracker.ietf.org/doc/html/rfc5289) Conclusion: SECURE. |
| `TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256` | Transport Layer Security (TLS) Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) see: [RFC 5289 — TLS Elliptic Curve Cipher Suites with SHA-256/384](https://datatracker.ietf.org/doc/html/rfc5289) Conclusion: RECOMMENDED. |
| `TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384` | Transport Layer Security (TLS) Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) see: [RFC 5289 — TLS Elliptic Curve Cipher Suites with SHA-256/384](https://datatracker.ietf.org/doc/html/rfc5289) Conclusion: SECURE. |
| `TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384` | Transport Layer Security (TLS) Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) see: [RFC 5289 — TLS Elliptic Curve Cipher Suites with SHA-256/384](https://datatracker.ietf.org/doc/html/rfc5289) Conclusion: RECOMMENDED. |
| `TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256` | Transport Layer Security (TLS) Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) see: [RFC 7905 — ChaCha20-Poly1305 Cipher Suites for TLS](https://datatracker.ietf.org/doc/html/rfc7905) Conclusion: SECURE. |
| `TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256` | Transport Layer Security (TLS) Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) see: [RFC 7905 — ChaCha20-Poly1305 Cipher Suites for TLS](https://datatracker.ietf.org/doc/html/rfc7905) Conclusion: RECOMMENDED. |
| `TLS_AES_128_GCM_SHA256` | Transport Layer Security (TLS) Protocol Version 1.3 see [RFC 8446 — TLS Protocol Version 1.3](https://datatracker.ietf.org/doc/html/rfc8446) Conclusion: RECOMMENDED. |
| `TLS_AES_256_GCM_SHA384` | Transport Layer Security (TLS) Protocol Version 1.3 see [RFC 8446 — TLS Protocol Version 1.3](https://datatracker.ietf.org/doc/html/rfc8446) Conclusion: RECOMMENDED. |
| `TLS_CHACHA20_POLY1305_SHA256` | Transport Layer Security (TLS) Protocol Version 1.3 see [RFC 8446 — TLS Protocol Version 1.3](https://datatracker.ietf.org/doc/html/rfc8446) Conclusion: RECOMMENDED. |
| `TLS_FALLBACK_SCSV` | Signaling cipher suite value used to prevent protocol downgrade attacks. |
| `UNKNOWN` | The cipher suite is not recognized. |

## Used by

- [`TLS`](https://wartiva.com/api-docs/types/tls.html) type: Reports on SSL (Secure Sockets Layer) and TLS (Transport Layer Security).

## Example

### Example

```json
"TLS_RSA_WITH_RC4_128_SHA"

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
