Skip to main content

Domain Mode - TLS/SSL Scanner

Applies to:
TLS 1.2 / TLS 1.3Certificate Chain ExtractionCipher Suite & Key Exchange DetectionPQC Readiness & Quantum Risk Score
Status

Implemented. Built in Rust for the TLS handshake and certificate analysis.

Overview​

Domain mode performs active TLS scanning of remote endpoints. It connects to a target host, performs a TLS handshake, and extracts the full certificate chain (server certificate, intermediates, and root). It also detects the negotiated cipher suite and key exchange algorithm.

By default it runs a classic SSL/TLS audit (certificate, cipher-suite, protocol, and vulnerability information). Pass --pqc to run the Post-Quantum readiness scan instead — a live key-exchange probe that produces the PQC readiness report and the composite Quantum Risk Score.

Subdomain discovery is a Cockpit feature, not a CLI flag

The Cockpit's Domain scan source can optionally discover and scan subdomains. The standalone dke-scanner-agent domain CLI command does not expose a subdomain-discovery flag — pass every target explicitly (comma-separated) or run it from the Cockpit scan wizard.

How It Works​

Domain Mode Flow

1

TCP Connection

Connects to target host and port (default: 443)

2

TLS Handshake

Performs TLS handshake via rustls (TLS 1.2/1.3, ring backend)

3

Chain Extraction

Extracts full certificate chain: server + intermediates + root

4

Cipher Detection

Identifies negotiated cipher suite and key exchange method

5

Crypto Analysis

Analyzes algorithms, key sizes, and quantum vulnerability

6

Risk Scoring

Calculates quantum risk scores for each certificate

Features​

1 TLS 1.2 & 1.3 Support

Connects using rustls with ring backend, supporting TLS 1.2 and TLS 1.3 handshakes

2 Full Certificate Chain

Extracts the complete chain: leaf (server) certificate, intermediate CAs, and root CA

3 Cipher Suite & Key Exchange

Detects the negotiated cipher suite and key exchange algorithm used in the handshake

4 Post-Quantum Readiness

--pqc runs a live key-exchange probe and produces the PQC readiness report plus Quantum Risk Score

5 Multiple Targets & Ports

Comma-separated target hosts (domain, IP, or CIDR range) and comma-separated ports in a single invocation

6 Multiple Output Formats

Classic audit: report (SSLyze-style, default), table, JSON, or summary. PQC scan: report (default), JSON, or summary

Usage​

Basic Scanning​

# Classic SSL/TLS audit of a single domain on default port 443
dke-scanner-agent domain --target example.com

# Scan a custom port
dke-scanner-agent domain --target api.example.com --ports 8443

# Scan with output to file
dke-scanner-agent domain --target example.com --output scan-results.json --format json

Command-Line Options​

FlagDescriptionDefaultRequired
--target <HOSTS>Target hosts, comma-separated (domain, IP, or CIDR range)NoneYes
--ports <PORTS>Ports to scan, comma-separated443No
--timeout <SECS>Connection timeout in seconds per target10No
--concurrency <N>Maximum number of concurrent TLS connections20No
--retries <N>Retry attempts per target on connection failure1No
--pqcRun the Post-Quantum readiness scan (live key-exchange probe) instead of the classic SSL auditfalseNo
--jurisdiction <CODE>Jurisdiction code (eu, us, ae, us_nss, …) driving the QRS scoring profile — only applies with --pqccivilianNo
--output <FILE>Output file pathstdoutNo
--format <FMT>Classic SSL: report (default), table, json, or summary. PQC (--pqc): report (default), json, or summaryreportNo

Advanced Examples​

Architecture​

  1. Connects to each target host/port and performs the TLS handshake.
  2. Extracts the full certificate chain (server, intermediates, root).
  3. Records the negotiated cipher suite, key exchange and protocol version.
  4. Classic mode (default) produces the SSL/TLS audit — grade, protocols, cipher suites, vulnerabilities, compliance.
  5. With --pqc, runs a live key-exchange probe instead and produces the PQC readiness report and Quantum Risk Score.

Example Output​

{
"scan_metadata": {
"scanner_version": "1.0.0",
"scan_mode": "domain",
"scan_date": "2025-01-30T16:20:15Z"
},
"target": {
"hostname": "api.example.com",
"port": 443,
"ip_address": "93.184.216.34"
},
"tls_info": {
"protocol_version": "TLS 1.3",
"cipher_suite": "TLS_AES_256_GCM_SHA384",
"key_exchange": "X25519"
},
"certificates": [
{
"position": 0,
"type": "leaf",
"subject": "CN=api.example.com",
"issuer": "CN=DigiCert TLS RSA SHA256 2020 CA1",
"serial": "0A1B2C3D4E5F6789",
"not_before": "2024-01-01T00:00:00Z",
"not_after": "2025-12-31T23:59:59Z",
"algorithm": "RSA",
"key_size": 2048,
"signature_algorithm": "SHA256WithRSA",
"is_self_signed": false,
"is_ca": false,
"quantum_vulnerable": true,
"risk_assessment": {
"quantum_risk_score": 8.2,
"priority": "P1",
"severity": "HIGH"
}
},
{
"position": 1,
"type": "intermediate",
"subject": "CN=DigiCert TLS RSA SHA256 2020 CA1",
"issuer": "CN=DigiCert Global Root CA",
"algorithm": "RSA",
"key_size": 2048,
"is_ca": true,
"quantum_vulnerable": true
},
{
"position": 2,
"type": "root",
"subject": "CN=DigiCert Global Root CA",
"issuer": "CN=DigiCert Global Root CA",
"algorithm": "RSA",
"key_size": 2048,
"is_self_signed": true,
"is_ca": true,
"quantum_vulnerable": true
}
]
}

Key Limitations​

PQC readiness detection needs --pqc

Without --pqc, the classic SSL/TLS audit reports the negotiated key exchange as seen at the TLS-library level and does not run the live PQC probe. Use domain --pqc to get the PQC readiness report and Quantum Risk Score, which is the only mode that reliably distinguishes a hybrid post-quantum key exchange (e.g. X25519MLKEM768) from classical X25519.

Troubleshooting​

Best Practices​