Domain Mode - TLS/SSL Scanner
Domain Mode - TLS/SSL Scanner
TLS handshake analysis with full certificate chain extraction, cipher suite detection, and optional PQ key exchange detection
Implemented. Built in Rust for the TLS handshake and certificate analysis.
Overview
Domain mode performs active TLS scanning of remote endpoints. It connects to a target host, performs a TLS handshake, and extracts the full certificate chain (server certificate, intermediates, and root). It also detects the negotiated cipher suite and key exchange algorithm.
By default it runs a classic SSL/TLS audit (certificate, cipher-suite, protocol, and vulnerability information). Pass --pqc to run the Post-Quantum readiness scan instead — a live key-exchange probe that produces the PQC readiness report and the composite Quantum Risk Score.
The Cockpit's Domain scan source can optionally discover and scan subdomains. The standalone dke-scanner-agent domain CLI command does not expose a subdomain-discovery flag — pass every target explicitly (comma-separated) or run it from the Cockpit scan wizard.
How It Works
Domain Mode Flow
TCP Connection
Connects to target host and port (default: 443)
TLS Handshake
Performs TLS handshake via rustls (TLS 1.2/1.3, ring backend)
Chain Extraction
Extracts full certificate chain: server + intermediates + root
Cipher Detection
Identifies negotiated cipher suite and key exchange method
Crypto Analysis
Analyzes algorithms, key sizes, and quantum vulnerability
Risk Scoring
Calculates quantum risk scores for each certificate
Features
TLS 1.2 & 1.3 Support
Connects using rustls with ring backend, supporting TLS 1.2 and TLS 1.3 handshakes
Full Certificate Chain
Extracts the complete chain: leaf (server) certificate, intermediate CAs, and root CA
Cipher Suite & Key Exchange
Detects the negotiated cipher suite and key exchange algorithm used in the handshake
Post-Quantum Readiness
--pqc runs a live key-exchange probe and produces the PQC readiness report plus Quantum Risk Score
Multiple Targets & Ports
Comma-separated target hosts (domain, IP, or CIDR range) and comma-separated ports in a single invocation
Multiple Output Formats
Classic audit: report (SSLyze-style, default), table, JSON, or summary. PQC scan: report (default), JSON, or summary
Usage
Basic Scanning
# Classic SSL/TLS audit of a single domain on default port 443
dke-scanner-agent domain --target example.com
# Scan a custom port
dke-scanner-agent domain --target api.example.com --ports 8443
# Scan with output to file
dke-scanner-agent domain --target example.com --output scan-results.json --format json
Command-Line Options
| Flag | Description | Default | Required |
|---|---|---|---|
| --target <HOSTS> | Target hosts, comma-separated (domain, IP, or CIDR range) | None | Yes |
| --ports <PORTS> | Ports to scan, comma-separated | 443 | No |
| --timeout <SECS> | Connection timeout in seconds per target | 10 | No |
| --concurrency <N> | Maximum number of concurrent TLS connections | 20 | No |
| --retries <N> | Retry attempts per target on connection failure | 1 | No |
| --pqc | Run the Post-Quantum readiness scan (live key-exchange probe) instead of the classic SSL audit | false | No |
| --jurisdiction <CODE> | Jurisdiction code (eu, us, ae, us_nss, …) driving the QRS scoring profile — only applies with --pqc | civilian | No |
| --output <FILE> | Output file path | stdout | No |
| --format <FMT> | Classic SSL: report (default), table, json, or summary. PQC (--pqc): report (default), json, or summary | report | No |
Advanced Examples
Architecture
- Connects to each target host/port and performs the TLS handshake.
- Extracts the full certificate chain (server, intermediates, root).
- Records the negotiated cipher suite, key exchange and protocol version.
- Classic mode (default) produces the SSL/TLS audit — grade, protocols, cipher suites, vulnerabilities, compliance.
- With
--pqc, runs a live key-exchange probe instead and produces the PQC readiness report and Quantum Risk Score.
Example Output
{
"scan_metadata": {
"scanner_version": "1.0.0",
"scan_mode": "domain",
"scan_date": "2025-01-30T16:20:15Z"
},
"target": {
"hostname": "api.example.com",
"port": 443,
"ip_address": "93.184.216.34"
},
"tls_info": {
"protocol_version": "TLS 1.3",
"cipher_suite": "TLS_AES_256_GCM_SHA384",
"key_exchange": "X25519"
},
"certificates": [
{
"position": 0,
"type": "leaf",
"subject": "CN=api.example.com",
"issuer": "CN=DigiCert TLS RSA SHA256 2020 CA1",
"serial": "0A1B2C3D4E5F6789",
"not_before": "2024-01-01T00:00:00Z",
"not_after": "2025-12-31T23:59:59Z",
"algorithm": "RSA",
"key_size": 2048,
"signature_algorithm": "SHA256WithRSA",
"is_self_signed": false,
"is_ca": false,
"quantum_vulnerable": true,
"risk_assessment": {
"quantum_risk_score": 8.2,
"priority": "P1",
"severity": "HIGH"
}
},
{
"position": 1,
"type": "intermediate",
"subject": "CN=DigiCert TLS RSA SHA256 2020 CA1",
"issuer": "CN=DigiCert Global Root CA",
"algorithm": "RSA",
"key_size": 2048,
"is_ca": true,
"quantum_vulnerable": true
},
{
"position": 2,
"type": "root",
"subject": "CN=DigiCert Global Root CA",
"issuer": "CN=DigiCert Global Root CA",
"algorithm": "RSA",
"key_size": 2048,
"is_self_signed": true,
"is_ca": true,
"quantum_vulnerable": true
}
]
}
Key Limitations
Without --pqc, the classic SSL/TLS audit reports the negotiated key exchange as seen at the TLS-library level and does not run the live PQC probe. Use domain --pqc to get the PQC readiness report and Quantum Risk Score, which is the only mode that reliably distinguishes a hybrid post-quantum key exchange (e.g. X25519MLKEM768) from classical X25519.