OpenSSL Trace
SSL/TLS Handshake Trace
Run handshake using openssl compiled with enable-ssl-trace. This shows detailed SSL/TLS protocol information including cipher negotiation, certificate verification, and protocol version.
About OpenSSL Trace
The CSR.plus SSL/TLS Tracer walks through the entire connection lifecycle to a host — DNS resolution, TCP connect, and the TLS handshake — and shows the protocol, cipher suite, and certificates returned at each stage. It is built for diagnosing TLS errors that other checkers hide.
This online tool provides the same visibility as running openssl s_client -trace, but without a terminal. When a handshake fails, you can see the exact step that broke: a DNS failure, a refused TCP connection, a TLS version mismatch, or a certificate error. It is the debugging tool for SSL/TLS troubleshooting.
Why use
- Logs DNS, TCP, and every TLS handshake stage in order
- Pinpoints the exact step where a connection fails
- Shows negotiated TLS version, cipher suite, and certificate chain
- No terminal needed — a browser-based openssl s_client trace
How to use
- Enter the host (and optional port) you want to trace.
- The tracer logs DNS, TCP, and each TLS handshake step in order.
- Find the exact stage where the connection fails or degrades.
- Inspect the negotiated version, cipher, and presented certificates to fix the issue.
Frequently asked questions
▸When should I use the tracer instead of a checker?
Use it when a connection fails or shows odd behaviour — it exposes the exact step where things break.
▸Does it support custom ports?
Yes. Trace mail, database, or internal services by specifying their port.
▸Can it reveal weak TLS settings?
Yes. It reports the negotiated TLS version and cipher so outdated configurations are easy to spot.
▸How does this compare to openssl s_client -trace?
It provides equivalent step-by-step visibility of the handshake through a web interface, with no command line required.