🔒 TLS Cipher Suite Reference

Search common TLS 1.2 and TLS 1.3 cipher suites by name to see their TLS version and current recommendation.

Reading a suite name

A TLS 1.2 name is four decisions in a row. Take ECDHE-RSA-AES128-GCM-SHA256: ephemeral elliptic-curve Diffie-Hellman for key exchange, an RSA certificate to authenticate the server, AES-128 in GCM to encrypt the data, SHA-256 for the handshake hash. The ephemeral part is what gives forward secrecy - the session key is thrown away, so a stolen private key cannot decrypt yesterday's traffic. That is precisely what the two red non-PFS rows lack: in AES128-SHA the client encrypts the secret to the server's long-term RSA key, and anyone holding that key later can read every recorded session.

TLS 1.3 names are shorter because two of the four choices are gone. TLS_AES_128_GCM_SHA256 states only the AEAD cipher and the hash; key exchange is always ephemeral and the signature algorithm is negotiated separately, so the weak combinations cannot be expressed at all.

The table mixes both naming conventions, and the filter matches the name text only. gcm returns five rows, ecdhe five, cbc just one - the IANA-style row - even though the 3DES and AES-SHA suites are CBC too.

Setting and testing them

openssl ciphers -v 'ECDHE+AESGCM:ECDHE+CHACHA20'   # what your build supports
openssl s_client -connect example.com:443 -cipher ECDHE-RSA-AES128-GCM-SHA256

In nginx and Apache the cipher list applies to TLS 1.2 and below only; TLS 1.3 suites are configured separately, or not at all, because all three are safe. The larger win is switching off TLS 1.0 and 1.1, which removes the broken rows here without maintaining a list.

Frequently asked questions

Which cipher suites should a server offer in 2026?

The three TLS 1.3 suites, plus ECDHE with AES-GCM or ChaCha20-Poly1305 for TLS 1.2 clients. Everything without ECDHE, and everything using CBC, RC4 or 3DES, can go.

What does the SHA256 at the end mean?

Not the certificate signature. In a TLS 1.2 suite it is the hash used by the handshake PRF and, for CBC suites, the MAC. GCM suites carry their own authentication, so the hash only affects key derivation.

Is ChaCha20-Poly1305 weaker than AES-256?

No. It is a 256-bit stream cipher with its own authenticator, chosen because phones and other CPUs without AES instructions run it several times faster than AES in software.