Reports on SSL (Secure Sockets Layer) and TLS (Transport Layer Security).
Fields
| Field Name | Description |
|---|---|
versionNumber - Int!
|
TLS version number used by the connection (e.g. 0x0301). |
version - TLSVersion!
|
TLS version represented as an enum (e.g. TLS_1_0). |
handshakeComplete - Boolean!
|
True if the handshake has concluded. |
didResume - Boolean!
|
True if this connection was successfully resumed from a previous session with a session ticket or similar mechanism. |
cipherSuiteNumber - Int!
|
The cipher suite number negotiated for the connection (e.g. 0x0005). |
cipherSuite - TLSCipherSuite!
|
Cipher suite represented as an enum (e.g. TLS_RSA_WITH_RC4_128_SHA). |
certVerifyError - String
|
Contains the error message if certificate validation failed. |
certVerifyOk - Boolean!
|
True when the certificate chain the service presented validates against the system trust store and is bound to the address this scan reached the service at. Because services are scanned by address, a certificate issued for a DNS name with no matching IP SAN reports false with the reason in certVerifyError — that is a name mismatch for this connection, not necessarily a misconfigured service. |
peerCertificates - [TLSCertificate!]
|
The certificate chain the service presented, capped at a configured number of certificates, so a pathologically long chain is stored as a prefix rather than in full. certVerifyOk is always computed over the complete presented chain regardless of this cap, so a truncated list never explains the verdict and must not be read as the evidence behind it. |
supportedVersions - [TLSVersion!]
|
Every protocol version the service accepted when probed, not just the one this scan negotiated. A service that negotiated TLS 1.3 with the scanner may still accept TLS 1.0 from a client that asks for it, and only this field reveals that. Null when version enumeration is disabled or the service accepted nothing. |
supportedCipherSuites - [TLSCipherSuite!]
|
Every cipher suite the service accepted across all supported versions, discovered by offering the suites not yet selected until the service declines them all. When enumeration ran this includes the cipherSuite field above, which records only the suite this scan negotiated. Null when cipher-suite enumeration is disabled. |
serverPreferenceEnforced - Boolean
|
True when the service imposes its own cipher-suite order rather than honoring the client's preference. Server-enforced order resists a client being steered onto the weakest mutually supported suite. Null when the check did not run or could not conclude. |
enumerationTruncated - Boolean!
|
True when the probe budget was exhausted before enumeration finished, making supportedVersions and supportedCipherSuites a lower bound rather than the service's complete configuration. Treat a truncated result as incomplete evidence, never as proof that nothing else is accepted. |
ocspStapled - Boolean!
|
Whether the service stapled an OCSP response to its handshake, or agreed to staple one where the scanner that reached it could see only that agreement. A service that staples nothing forces every client to reach the issuer's responder to learn whether its certificate is still valid, and most clients will not, so a revoked certificate keeps being accepted. |
revocationStatus - RevocationStatus
|
Whether the certificate has been revoked by its issuer. Decided after the scan, when the observation is processed, so a service seen for the first time may report UNKNOWN until then. UNKNOWN also means no revocation source could be consulted, which is an ordinary outcome for a private certificate authority or a short-lived certificate that publishes none. |
revocationSource - RevocationSource
|
What produced revocationStatus: an OCSP response the service stapled to its own handshake, an OCSP responder queried directly, or a certificate revocation list fetched from the issuing authority. |
revocationReason - RevocationReason
|
Why the certificate was revoked, from the issuer's revocation entry. Meaningful only when revocationStatus is REVOKED. KEY_COMPROMISE is the one that matters most: it means the private key is in someone else's hands, so anything it signed is suspect. |
revokedAt - Time
|
When the issuing authority recorded the revocation. |
Used by
DNStype: Domain Name System (DNS) service.FTPtype: File Transfer Protocol (FTP) is a standard communication protocol used for the transfer of computer files from a server to a client on a computer…HTTPtype: Hypertext Transfer Protocol (HTTP) service, including: HTTP, HTTPS, and HTTP over TLS.IPPtype: Internet Printing Protocol (IPP) service.ServiceReportunion: The service specific data structure describing details of the specific type of service.SMTPtype: SMTP Service.
Example
Example
{
"versionNumber": 987,
"version": "SSL_2_0",
"handshakeComplete": false,
"didResume": true,
"cipherSuiteNumber": 987,
"cipherSuite": "TLS_RSA_WITH_RC4_128_SHA",
"certVerifyError": "xyz789",
"certVerifyOk": false,
"peerCertificates": [TLSCertificate],
"supportedVersions": ["SSL_2_0"],
"supportedCipherSuites": ["TLS_RSA_WITH_RC4_128_SHA"],
"serverPreferenceEnforced": false,
"enumerationTruncated": true,
"ocspStapled": false,
"revocationStatus": "GOOD",
"revocationSource": "NONE",
"revocationReason": "NOT_SPECIFIED",
"revokedAt": "2021-10-07T18:23:25.829Z"
}