← All drills

TLS / Encryption Config Auditor

What you'll be able to do

Build the scanner behind SSL Labs and Mozilla Observatory — point it at a server and get a letter grade for the encryption protecting its users, catching expired certs, dead protocols, and weak ciphers before an attacker exploits them.

⌁ TLS posture scanning is how the web is kept encrypted — Qualys SSL Labs, Cloudflare, and Mozilla grade millions of sites, and every security team audits what protects its data in transit.
Start this internship
Create an account to unlock the 8 sections, the workbench, and askThili.
Begin

Sections

1. The TLS / Encryption Config Auditor
🔒 locked
2. Lesson 1 - What TLS protects, and what breaks it
🔒 locked
3. Lesson 2 - Read a certificate
🔒 locked
4. Lesson 3 - Is the certificate healthy?
🔒 locked
5. Lesson 4 - Protocols & ciphers
🔒 locked
6. Lesson 5 - Grade it
🔒 locked
7. Lesson 6 - Audit a fleet
🔒 locked
8. Lesson 7 - Ship your TLS auditor
🔒 locked

Dig deeper

📄The Matter of Heartbleed (Durumeric et al., 2014, IMC) — measuring TLS in the wild
paper
🔗Mozilla — Server Side TLS configuration guidelines
docs
🔗Qualys SSL Labs — SSL Server Rating Guide (grading methodology)
docs

Part of these learning paths

I'm a security professional and I want to test AI/ML systems for vulnerabilities
View path →