About SSL Labs

SSL Labs is a collection of documents, tools and thoughts related to SSL. It’s an attempt to better understand how SSL is deployed, and an attempt to make it better. I hope that, in time, SSL Labs will grow into a forum where SSL will be discussed and improved.

SSL Labs is a non-commercial research effort, and we welcome participation from any individual and organization interested in SSL.

SSL/TLS Deployment Best Practices

The SSL/TLS Deployment Best Practices document provides clear and concise instructions to help overworked administrators and programmers spend the minimum time possible to deploy a secure site or web application. The focus is on advice that is practical and easy to understand.

SSL Server Test

The SSL server test is an online service that enables you to inspect the configuration of any public SSL web server.

SSL Client Test

The SSL client test shows the SSL/TLS capabilities of your browser.

SSL Server Rating Guide

SSL Server Rating Guide aims to establish a straightforward assessment methodology, allowing administrators to assess SSL server configuration confidently without the need to become SSL experts.

User Agent Capabilities

Our database of user agents and their SSL/TLS capabilities, covering a wide range of popular devices, browsers and tools.

HTTP Client Fingerprinting Using SSL Handshake Analysis

Different programs (that make use of SSL) often use different cipher suites. By observing the list of supported cipher suites one can often guess the make of the SSL client on the other side.

SSL Threat Model

A threat model that covers the SSL security ecosystem, consisting of SSL, TLS and PKI.

Internet SSL Survey

The Internet SSL Survey is an effort to understand how SSL is used on the public Internet.