Editorial author: XRENN Labs s.r.o. · Updated:
What a successful handshake means
Certificate validation and protocol negotiation answer different questions. A certificate binds an identity under the client's trust rules; the protocol protects the session. IETF guidance recommends TLS 1.3 and retaining properly configured TLS 1.2 where needed, while rejecting obsolete protocol versions.
Sources: IETF RFC 9325 — Secure use of TLS
What our scanner measures
The scanner opens a connection on port 443 with hostname verification and SNI. It records the certificate issuer and expiry plus the protocol and cipher negotiated by that connection. The selected endpoint matters: a CDN or reverse proxy may terminate TLS before traffic reaches the application server.
One connection is not a protocol matrix
Negotiating TLS 1.3 does not prove that the server refuses every older protocol. Our handshake is not an exhaustive cipher enumeration, revocation audit or test of every load-balancer node. The displayed grade is XRENN™'s assessment of these checks, not a Qualys SSL Labs grade. A connection timeout does not prove HTTPS is absent.
A safe renewal or configuration change
Identify the component serving the certificate, its full chain and all names it must cover. Test renewal automation and configuration in the relevant environment, agree on rollback and avoid changing unrelated applications at the same time. Reserve broader protocol and cipher validation for an explicitly agreed scope.
What to compare after the change
Run a new scan against the same hostname and check the new expiry, trust validation and negotiated protocol. Check additional endpoints separately if the service uses several termination points. Keep the observation time and configuration change together; a later renewal failure cannot be ruled out by today's result.
Editorial method and primary sources
These explanations are checked against the implemented scanner scope and the references below. They distinguish public observations from checks requiring authorized internal access. A content update is not a customer audit or an independently certified review.