Decodificador de suites de cifrado
Introduce una suite de cifrado TLS, como nombre IANA, nombre OpenSSL o GnuTLS, o un punto de código hexadecimal, para desglosarla en su intercambio de claves, autenticación, cifrado, modo y MAC, con una lectura de seguridad en lenguaje claro y la recomendación oficial de IANA. Se ejecuta por completo en tu navegador contra una copia incorporada del registro de IANA.
TLS y transporteLa decodificación se ejecuta localmente contra una copia incorporada del registro de suites de cifrado TLS de IANA. No se envía nada a ningún sitio.
Grupos de intercambio de claves
TLS negocia el grupo de acuerdo de claves por separado de la suite de cifrado, en la extensión supported_groups. Como "harvest now, decrypt later" impulsa el paso al intercambio de claves poscuántico, los grupos híbridos siguientes combinan una curva clásica con ML-KEM.
- X25519MLKEM7680x11EC
Combina X25519 con ML-KEM-768
- SecP256r1MLKEM7680x11EB
Combina secp256r1 (P-256) con ML-KEM-768
- SecP384r1MLKEM10240x11ED
Combina secp384r1 (P-384) con ML-KEM-1024
- curveSM2MLKEM7680x11EE
Combina SM2 con ML-KEM-768
- X25519Kyber768Draft000x6399
Combina X25519 con Kyber768 (draft)
- SecP256r1Kyber768Draft000x639A
Combina secp256r1 (P-256) con Kyber768 (draft)
- x255190x001D
- x4480x001E
- secp256r10x0017
- secp384r10x0018
- secp521r10x0019
- secp224r10x0015
- secp192r10x0013
- ffdhe20480x0100
- ffdhe30720x0101
- ffdhe40960x0102
- ffdhe61440x0103
- ffdhe81920x0104
X25519MLKEM768 es el grupo híbrido que la mayoría de los navegadores ya envían de forma predeterminada.
All results are computed locally from the cipher suite you enter. The code points, names, and the IANA "Recommended" and DTLS-OK flags come from a bundled snapshot of the IANA TLS Cipher Suite registry; the structural breakdown (key exchange, authentication, cipher, mode, MAC) and the security read-out are derived in your browser. Nothing is looked up remotely.
- IANA TLS Cipher Suites registryAuthoritative code points, names, and the Recommended / DTLS-OK flags
- RFC 8446 (TLS 1.3)TLS 1.3 cipher-suite form (symmetric cipher and hash only)
- RFC 9846 (TLS 1.3, current revision)The December 2025 revision of TLS 1.3, obsoleting RFC 8446; the cipher-suite form and the five suites carry over unchanged
- RFC 8447Meaning of the "Recommended" column (Y / N / D)
- RFC 7465RC4 prohibited for TLS
- RFC 84293DES and IDEA deprecated for TLS
- ciphersuite.infoOpenSSL and GnuTLS cross-names
- The Illustrated TLS 1.2 Connection (Michael Driscoll)Byte-by-byte annotated TLS 1.2 handshake, showing the negotiated suite on the wire
- The Illustrated TLS 1.3 Connection (Michael Driscoll)Byte-by-byte annotated TLS 1.3 handshake, showing the short suite and separate key_share negotiation