🔒 TLS Cipher Suite Reference
Search common TLS 1.2 and TLS 1.3 cipher suites by name to see their TLS version and current recommendation.
Reading a suite name
A TLS 1.2 name is four decisions in a row. Take
ECDHE-RSA-AES128-GCM-SHA256: ephemeral elliptic-curve Diffie-Hellman
for key exchange, an RSA certificate to authenticate the server, AES-128 in GCM to
encrypt the data, SHA-256 for the handshake hash. The ephemeral part is what gives
forward secrecy - the session key is thrown away, so a stolen private key cannot
decrypt yesterday's traffic. That is precisely what the two red non-PFS rows lack:
in AES128-SHA the client encrypts the secret to the server's long-term
RSA key, and anyone holding that key later can read every recorded session.
TLS 1.3 names are shorter because two of the four choices are gone.
TLS_AES_128_GCM_SHA256 states only the AEAD cipher and the hash;
key exchange is always ephemeral and the signature algorithm is negotiated
separately, so the weak combinations cannot be expressed at all.
gcm returns five rows, ecdhe five,
cbc just one - the IANA-style row - even though the 3DES and AES-SHA
suites are CBC too.Setting and testing them
openssl ciphers -v 'ECDHE+AESGCM:ECDHE+CHACHA20' # what your build supports
openssl s_client -connect example.com:443 -cipher ECDHE-RSA-AES128-GCM-SHA256
In nginx and Apache the cipher list applies to TLS 1.2 and below only; TLS 1.3 suites are configured separately, or not at all, because all three are safe. The larger win is switching off TLS 1.0 and 1.1, which removes the broken rows here without maintaining a list.
Frequently asked questions
Which cipher suites should a server offer in 2026?
The three TLS 1.3 suites, plus ECDHE with AES-GCM or ChaCha20-Poly1305 for TLS 1.2 clients. Everything without ECDHE, and everything using CBC, RC4 or 3DES, can go.
What does the SHA256 at the end mean?
Not the certificate signature. In a TLS 1.2 suite it is the hash used by the handshake PRF and, for CBC suites, the MAC. GCM suites carry their own authentication, so the hash only affects key derivation.
Is ChaCha20-Poly1305 weaker than AES-256?
No. It is a 256-bit stream cipher with its own authenticator, chosen because phones and other CPUs without AES instructions run it several times faster than AES in software.