Optional categories are off until you choose. You can change or withdraw your choice using Cookie settings in the footer.

XRENN Labs s.r.o.

Security guides

TLS and certificates: a valid connection is only the starting point

HTTPS protects a connection. A valid certificate does not establish that the application behind it is secure, patched or correctly authorized.

Editorial author: XRENN Labs s.r.o. · Updated:

What a successful handshake means

Certificate validation and protocol negotiation answer different questions. A certificate binds an identity under the client's trust rules; the protocol protects the session. IETF guidance recommends TLS 1.3 and retaining properly configured TLS 1.2 where needed, while rejecting obsolete protocol versions.

Sources: IETF RFC 9325 — Secure use of TLS

What our scanner measures

The scanner opens a connection on port 443 with hostname verification and SNI. It records the certificate issuer and expiry plus the protocol and cipher negotiated by that connection. The selected endpoint matters: a CDN or reverse proxy may terminate TLS before traffic reaches the application server.

One connection is not a protocol matrix

Negotiating TLS 1.3 does not prove that the server refuses every older protocol. Our handshake is not an exhaustive cipher enumeration, revocation audit or test of every load-balancer node. The displayed grade is XRENN™'s assessment of these checks, not a Qualys SSL Labs grade. A connection timeout does not prove HTTPS is absent.

A safe renewal or configuration change

Identify the component serving the certificate, its full chain and all names it must cover. Test renewal automation and configuration in the relevant environment, agree on rollback and avoid changing unrelated applications at the same time. Reserve broader protocol and cipher validation for an explicitly agreed scope.

What to compare after the change

Run a new scan against the same hostname and check the new expiry, trust validation and negotiated protocol. Check additional endpoints separately if the service uses several termination points. Keep the observation time and configuration change together; a later renewal failure cannot be ruled out by today's result.

Editorial method and primary sources

These explanations are checked against the implemented scanner scope and the references below. They distinguish public observations from checks requiring authorized internal access. A content update is not a customer audit or an independently certified review.

Related guides

Expert guarantor

Cybersecurity, NIS2 & AI with Guarantor.

Direct contact with the expert guarantor for ISO 27001 ISMS, new Czech Cyber Security Act (ZKB 264/2025 Sb.) / NIS2 compliance, penetration testing, and world-class AI security.

Whether you are addressing the requirements of the new Czech Cyber Security Act (ZKB 264/2025 Sb.), the European NIS2 directive, ISO/IEC 27001 certification, or securely deploying frontier AI models and offline EdgeGuardian appliances, send your project inquiry to schedule an expert consultation.

Expertise & Diplomas

ISO/IEC 27001:2023 Lead Auditor

Information Security Management (ISMS), audit certification, and security policy implementation.

MBA Cybersecurity Academic Degree

Master of Business Administration – strategic and technical cybersecurity governance.

NIS2 & ZKB 264/2025 Sb. Compliance

Guarantor of compliance with the new Cyber Security Act and EU NIS2 directive.

AI & LLM Security Frontier AI

World-class frontier LLM model security, AI Red Teaming, and EdgeAI defense.