Barrion Docs
Passive Scanning

TLS / SSL

What Barrion checks when it evaluates your site's HTTPS configuration and certificate.

Barrion checks whether your website uses a valid, properly configured security certificate and strong encryption. A failing TLS check means visitors' browsers may show security warnings, or data sent between your site and its users could be at risk.

What Barrion Checks

HTTPS Enabled

Barrion verifies that your site is accessible over HTTPS and that any plain HTTP requests are redirected to the secure version. If your site is not using HTTPS, all data between your server and visitors travels without encryption.

Severity: High

TLS Version

Barrion checks that your site is using a modern, supported version of the TLS security protocol (1.2 or 1.3). Older versions have known weaknesses and are no longer considered safe.

Severity: High

Deprecated TLS Versions Supported

Even if your server prefers a modern TLS version, Barrion checks whether it still accepts connections from older, insecure versions. This can allow attackers to force a weaker connection.

Severity: Medium

Certificate Expiry

Barrion checks how many days remain before your TLS certificate expires. An expired certificate causes browsers to block visitors with a security warning.

Severity: High (expired or within 7 days), Medium (within 30 days)

Certificate Validity

Barrion verifies that the certificate covers the correct domain name and that the full certificate chain is trusted. A mismatch or broken chain causes browser security errors.

Severity: High

Cipher Strength

Barrion checks the strength of the encryption used when connecting to your site. Weak encryption algorithms have known vulnerabilities that could allow attackers to intercept traffic.

Severity: Medium

OCSP Stapling

Barrion checks whether your server provides certificate revocation status directly during the connection. This is an optional best practice that improves performance and privacy.

Severity: Low

What to Do

If any TLS checks fail, share the finding with your developer or hosting provider. Most certificate and TLS configuration issues are resolved through your hosting control panel or by renewing your certificate. Barrion includes specific details about each issue in the finding description to help guide remediation.