✓ good
Post-quantum encryption is in normal use
The endpoint selected X25519MLKEM768 in a normal TLS 1.3 handshake. Authentication remains classical.
Readiness details
Key establishment
Post-quantumiNormal TLS selected X25519MLKEM768.
Authentication
ClassicaliThe server authentication key is ECDSA P-384.
Certificate chain
ClassicaliThe verified chain contains classical certificate signatures.
Deployment
ConsistentiTested address-family paths produced equivalent readiness results.
TLS baseline
HealthyiTLS 1.3 and certificate validation succeeded.
Harvest-now/decrypt-later: protected by the observed hybrid key establishment.
Connection details
- Host
- reelix.h4ck.me
- Port
- 443
- SNI
- reelix.h4ck.me
- TLS version
- TLS 1.3
- Cipher
- TLS_AES_256_GCM_SHA384
- ALPN
- h2
- HelloRetryRequest
- no
- OCSP stapled
- no
- SCTs
- 0
Key establishment
Normal: X25519MLKEM768 · PQ-only: X25519MLKEM768
Certificates
Verified chain
leafCN=reelix.h4ck.me
verifiedCN=YE2,O=Let's Encrypt,C=US
verifiedCN=Root YE,O=ISRG,C=US
root_or_lastCN=ISRG Root X2,O=Internet Security Research Group,C=US