## TL;DR
testssl.sh is a single bash script that probes an HTTPS endpoint and reports which TLS protocols, cipher suites, and cert problems it has. Run it against your own host, read the graded findings, and fix what it flags. It takes a few minutes and gives you the evidence you need before and after any TLS change.

## The query
```
how to check your TLS config with testssl.sh
```

## Use this when
- You hardened TLS settings and want to confirm only strong protocols and ciphers are offered
- You need a repeatable pre-change and post-change TLS baseline for a runbook
- You inherited a server and want to see what its HTTPS actually supports
- You are prepping for an audit and want to find protocol issues yourself first

## Not for
- Scanning hosts you do not own or have written permission to test
- Performance or load testing; this is a config audit, not a stress tool
- Replacing your monitoring; run it on change and on a schedule, not as live alerting
- Fixing certificate issuance or renewal; that is your CA or ACME setup's job

## Steps
1. Get testssl.sh on a machine you control. Clone the repo or download the script, and confirm it runs with `testssl.sh --version`. Expected output: the version string prints without errors.
2. Run it against your host. Use `testssl.sh https://example.com/` (swap in your own host) and let it finish; a full run takes a few minutes. Expected output: a long report with sections for protocols, ciphers, and server defaults.
3. Read the protocol section first. Anything below TLS 1.2 offered, especially SSL or TLS 1.0/1.1, should show as offered or not. Expected output: only TLS 1.2 and 1.3 listed as offered, older protocols marked not offered.
4. Read the cipher findings. Look for weak ciphers (RC4, 3DES, NULL, export-grade) and any that lack forward secrecy. Expected output: a list of offered ciphers you can compare against your server config.
5. Check the cert chain and validity section. It flags expired certs, missing intermediates, and weak signature algorithms. Expected output: chain validates cleanly, no expired or weak-algorithm warnings.
6. Fix, re-run, and save the report. Tighten the server config, run testssl.sh again to confirm the flags are gone, and store both reports as your before and after evidence. Expected output: the second run shows the flagged items resolved.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_GYzTiA_c0yQ48q51ED_OaA
