Cipher Suite Decoder
Enter a TLS cipher suite, as an IANA name, an OpenSSL or GnuTLS name, or a hex code point, to break it into its key exchange, authentication, cipher, mode, and MAC, with a plain-language security read-out and the official IANA recommendation. Runs entirely in your browser against a bundled copy of the IANA registry.
Decoding runs locally against a bundled copy of the IANA TLS Cipher Suite registry. Nothing is sent anywhere.
Key-exchange groups
TLS negotiates the actual key-agreement group separately from the cipher suite, in the supported_groups extension. As "harvest now, decrypt later" drives the move to post-quantum key agreement, the hybrid groups below pair a classical curve with ML-KEM.
- X25519MLKEM7680x11EC
Combines X25519 with ML-KEM-768
- SecP256r1MLKEM7680x11EB
Combines secp256r1 (P-256) with ML-KEM-768
- SecP384r1MLKEM10240x11ED
Combines secp384r1 (P-384) with ML-KEM-1024
- curveSM2MLKEM7680x11EE
Combines SM2 with ML-KEM-768
- X25519Kyber768Draft000x6399
Combines X25519 with Kyber768 (draft)
- SecP256r1Kyber768Draft000x639A
Combines secp256r1 (P-256) with Kyber768 (draft)
- x255190x001D
- x4480x001E
- secp256r10x0017
- secp384r10x0018
- secp521r10x0019
- secp224r10x0015
- secp192r10x0013
- ffdhe20480x0100
- ffdhe30720x0101
- ffdhe40960x0102
- ffdhe61440x0103
- ffdhe81920x0104
X25519MLKEM768 is the hybrid most browsers now send by default.
References
- IANA TLS Cipher Suites registry
- RFC 8446 - The Transport Layer Security (TLS) Protocol Version 1.3
- RFC 5246 - The Transport Layer Security (TLS) Protocol Version 1.2
- RFC 8447 - IANA Registry Updates for TLS and DTLS
- RFC 7465 - Prohibiting RC4 Cipher Suites
- RFC 8429 - Deprecate Triple-DES (3DES) and IDEA Cipher Suites for TLS
- IANA TLS Supported Groups registry
- draft-ietf-tls-ecdhe-mlkem - Post-quantum hybrid ECDHE-MLKEM Key Agreement for TLS 1.3
- RFC 7919 - Negotiated Finite Field Diffie-Hellman Ephemeral Parameters for TLS
- NIST FIPS 203 - Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM)
- ciphersuite.info - cipher suite catalogue