The sys admin's daily grind: SSLScan
Keychain for Life

If, like our author Charly, you manage SSL-secured servers, read on to discover a tool that you will definitely appreciate. It checks whether the complete security setup is up to date.
SSL-secured services are the rule today, rather than the exception. But, how can I quickly and easily check a large number of servers to see whether the encryption methods in use are still up to date? With the SSLScan tool [1].
In the simplest case, I can just call SSLScan with the URL of the website that I want to test: sslscan example.com
. Listing 1 shows that SSLScan simply tried a long list of ciphers and returned a status of Accepted, Rejected, or Failed for each one.
However, I am primarily interested in what ciphers the server accepts, not what it rejects. The following command:
[...]
Buy this article as PDF
(incl. VAT)