Security

TLS Cipher Suite Decoder

Decode a TLS cipher suite name or hex code into its key exchange, authentication, bulk cipher and MAC components, with a security assessment and the OpenSSL and IANA equivalents.

Last reviewed by the Radiatus Cloud team

Decoded suite appears here.

Need this handled by experts?

Radiatus runs VAPT, managed SOC & security engineering for regulated teams.

Book a free security consult

Four decisions encoded in one name

A TLS cipher suite name is a compound describing the whole cryptographic configuration of a connection. TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 says the key exchange is ephemeral elliptic curve Diffie-Hellman, the server authenticates with an RSA certificate, the bulk cipher is AES-128 in Galois/Counter Mode, and the hash used for the key derivation is SHA-256. Reading the name tells you whether the connection has forward secrecy, whether it is authenticated encryption, and whether any component is obsolete.

TLS 1.3 changed the naming

In TLS 1.3 the key exchange and authentication are negotiated separately from the cipher suite, so the suite names are much shorter: TLS_AES_128_GCM_SHA256 names only the AEAD cipher and the hash. There are five of them in total, all of which provide forward secrecy and authenticated encryption by construction. That deliberate reduction removed the possibility of negotiating a bad combination, which is the largest single security improvement in the protocol.

What to look for in a legacy suite

Anything without ECDHE or DHE has no forward secrecy, so a compromised server key decrypts every past session that was captured. CBC mode suites are vulnerable to a family of padding oracle and timing attacks and require careful implementation to be safe. RC4, 3DES, MD5 and SHA-1 are all broken to varying degrees. Any suite whose name contains EXPORT, NULL or anon should never appear in a configuration, and their presence usually indicates a default that was never reviewed.

Related tools

  • Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
  • Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
  • Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
  • Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.

Frequently Asked Questions

What is forward secrecy?

A property where compromising the server private key does not allow decryption of previously recorded sessions, because each session used an ephemeral key that was discarded. Suites with ECDHE or DHE provide it; those with plain RSA key exchange do not.

Why are TLS 1.3 suite names so short?

Because TLS 1.3 negotiates key exchange and authentication separately from the cipher suite. The suite names only the AEAD cipher and hash. There are five suites in total, all providing forward secrecy and authenticated encryption, which removes the possibility of negotiating a weak combination.

Is CBC mode unsafe?

It is not broken outright, but it has produced a long series of padding oracle and timing attacks including BEAST and Lucky Thirteen, and safe implementation is genuinely difficult. GCM and ChaCha20-Poly1305 are authenticated encryption modes that avoid the whole category, and they should be preferred.

What does the hash at the end mean?

In TLS 1.2 it is the hash used in the pseudorandom function for key derivation and, for non AEAD suites, in the message authentication code. It is not the certificate signature hash, which is a separate setting and a common point of confusion.

Should I configure an explicit cipher list?

Usually not. Modern defaults in OpenSSL and in the major web servers are well chosen and improve with each release, whereas a written list freezes at the day it was written. Configure one only where a compliance regime requires specific suites.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Paste a cipher suite name such as TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 or a hex code.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.