🛡 PQScan — Network PQC Readiness Report

Scan time: Monday, 15 June 2026 at 14:52:15 UTC  •  Duration: 4m34.607s

254
Targets
9
Alive Hosts
49
Open Ports
2
PQC Ready
0
PQC Partial
15
Not PQC Ready

Host Results

Ip Base.1 Docsis-Gateway.hsd1.va.adamznetwork.hidden
MAC: 8C:6A:8D:AD:56:4B OUI:8C:6A:8D   OS: Unknown (low)
● Risk: high 0/3 PQC ready
PortServiceProduct / Version TLS VerCipher SuiteCert TypeCert SubjectCert ExpiryCert Sig KEMSSH KEX PQC StatusNotes
443/tcp https HTTP 1.1 TLS 1.3 TLS_AES_128_GCM_SHA256 OV (Organization Validated) myrouter.io 2026-08-04 SHA256-RSA X25519 Not Ready
✓ Cert subject: myrouter.io
✓ Cert issuer: COMODO RSA Organization Validation Secure Server CA
✓ Cert type: OV (Organization Validated)
✓ Cert expiry: 2026-08-04
✓ Cert sig algo: SHA256-RSA
⚠ Certificate uses classical signature: SHA256-RSA
80/tcp http Unknown
✓ Not a TLS or SSH service
53/tcp dns Unknown
Ip Base.103 idrac-1P2RBP1.hsd1.va.adamznetwork.hidden
MAC: 78:2B:CB:08:BC:25 OUI:78:2B:CB   OS: Linux/Unix (high)
● Risk: high 0/4 PQC ready
PortServiceProduct / Version TLS VerCipher SuiteCert TypeCert SubjectCert ExpiryCert Sig KEMSSH KEX PQC StatusNotes
22/tcp ssh OpenSSH 5.2 diffie-hellman-group-exchange-sha256 diffie-hellman-group-exchange-sha1 diffie-hellman-group14-sha1 diffie-hellman-group1-sha1 Not Ready
✓ SSH banner: SSH-2.0-OpenSSH_5.2
✓ KEX algorithms: diffie-hellman-group-exchange-sha256, diffie-hellman-group-exchange-sha1, diffie-hellman-group14-sha1, diffie-hellman-group1-sha1
✓ Host key algorithms: ssh-rsa, ssh-dss
⚠ No PQC key exchange algorithms advertised
⚠ OpenSSH 5.2 is below PQC-ready version 8.5
✗ OpenSSH >= 8.5 supports sntrup761x25519 PQC hybrid KEX (detected v5.0, requires >= 8.5)
443/tcp https Unknown
✓ KEM probe: not a TLS handshake record (type=15)
⚠ TLS connect failed: remote error: tls: handshake failure
5900/tcp vnc Unknown
80/tcp http Mbedthis-Appweb 2.4.2 Unknown
✓ Not a TLS or SSH service
Ip Base.104 serverthree.hsd1.va.adamznetwork.hidden
MAC: 78:2B:CB:08:BC:24 OUI:78:2B:CB   OS: Linux/Unix (high)
● Risk: critical 0/3 PQC ready
PortServiceProduct / Version TLS VerCipher SuiteCert TypeCert SubjectCert ExpiryCert Sig KEMSSH KEX PQC StatusNotes
22/tcp ssh OpenSSH 7.4 curve25519-sha256 curve25519-sha256@libssh.org ecdh-sha2-nistp256 ecdh-sha2-nistp384 ecdh-sha2-nistp521 diffie-hellman-group-exchange-sha256 diffie-hellman-group16-sha512 diffie-hellman-group18-sha512 diffie-hellman-group-exchange-sha1 diffie-hellman-group14-sha256 diffie-hellman-group14-sha1 diffie-hellman-group1-sha1 Not Ready
✓ SSH banner: SSH-2.0-OpenSSH_7.4
✓ KEX algorithms: curve25519-sha256, curve25519-sha256@libssh.org, ecdh-sha2-nistp256, ecdh-sha2-nistp384, ecdh-sha2-nistp521, diffie-hellman-group-exchange-sha256, diffie-hellman-group16-sha512, diffie-hellman-group18-sha512, diffie-hellman-group-exchange-sha1, diffie-hellman-group14-sha256, diffie-hellman-group14-sha1, diffie-hellman-group1-sha1
✓ Host key algorithms: ssh-rsa, rsa-sha2-512, rsa-sha2-256, ecdsa-sha2-nistp256, ssh-ed25519
⚠ No PQC key exchange algorithms advertised
⚠ OpenSSH 7.4 is below PQC-ready version 8.5
✗ OpenSSH >= 8.5 supports sntrup761x25519 PQC hybrid KEX (detected v7.0, requires >= 8.5)
80/tcp http Unknown
✓ Not a TLS or SSH service
443/tcp https HTTP 1.1 TLS 1.2 TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 Self-Signed AkvasHypervisor.akvas.com 2033-11-07 SHA256-RSA Not Ready
✓ Cert subject: AkvasHypervisor.akvas.com
✓ Cert issuer: AkvasHypervisor.akvas.com
✓ Cert type: Self-Signed
✓ Cert expiry: 2033-11-07
✓ Cert sig algo: SHA256-RSA
✓ KEM probe: not a TLS handshake record (type=15)
⚠ Certificate uses classical signature: SHA256-RSA
Ip Base.150 server1.hsd1.va.adamznetwork.hidden
OS: Linux/Unix (high)
● Risk: low 1/2 PQC ready
PortServiceProduct / Version TLS VerCipher SuiteCert TypeCert SubjectCert ExpiryCert Sig KEMSSH KEX PQC StatusNotes
22/tcp ssh OpenSSH 10.2p1 mlkem768x25519-sha256 sntrup761x25519-sha512 sntrup761x25519-sha512@openssh.com curve25519-sha256 curve25519-sha256@libssh.org ecdh-sha2-nistp256 ecdh-sha2-nistp384 ecdh-sha2-nistp521 ext-info-s kex-strict-s-v00@openssh.com PQC Ready
✓ SSH banner: SSH-2.0-OpenSSH_10.2p1 Ubuntu-2ubuntu3.2
✓ KEX algorithms: mlkem768x25519-sha256, sntrup761x25519-sha512, sntrup761x25519-sha512@openssh.com, curve25519-sha256, curve25519-sha256@libssh.org, ecdh-sha2-nistp256, ecdh-sha2-nistp384, ecdh-sha2-nistp521, ext-info-s, kex-strict-s-v00@openssh.com
✓ Host key algorithms: rsa-sha2-512, rsa-sha2-256, ecdsa-sha2-nistp256, ssh-ed25519
✓ PQC KEX supported: mlkem768x25519-sha256 (ML-KEM-768 + X25519 hybrid (OpenSSH 9.9+)); sntrup761x25519-sha512@openssh.com (Streamlined NTRU + X25519 hybrid (OpenSSH 8.5+))
✓ PQC KEX is highest preference: mlkem768x25519-sha256
OpenSSH >= 8.5: sntrup761x25519 supported
OpenSSH >= 9.9: mlkem768x25519 supported
✓ OpenSSH >= 8.5 supports sntrup761x25519 PQC hybrid KEX
80/tcp http Apache 2.4.66 Unknown
✓ Not a TLS or SSH service
✓ Apache httpd PQC readiness depends on linked OpenSSL version
Ip Base.204
MAC: 26:3A:48:74:42:4E OUI:26:3A:48   OS: Linux/Unix (high)
● Risk: high 0/5 PQC ready
PortServiceProduct / Version TLS VerCipher SuiteCert TypeCert SubjectCert ExpiryCert Sig KEMSSH KEX PQC StatusNotes
587/tcp smtp Unknown
✓ KEM probe: not a TLS handshake record (type=32)
✓ No TLS detected (may require STARTTLS negotiation)
⚠ TLS connect failed: tls: first record does not look like a TLS handshake
443/tcp https HTTP 1.1 TLS 1.2 TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 DV (Domain Validated) *.adamkclark.com 2026-08-10 SHA256-RSA Not Ready
✓ Cert subject: *.adamkclark.com
✓ Cert issuer: R13
✓ Cert type: DV (Domain Validated)
✓ Cert expiry: 2026-08-10
✓ Cert sig algo: SHA256-RSA
✓ KEM probe: not a TLS handshake record (type=15)
⚠ Certificate uses classical signature: SHA256-RSA
⚠ HTTP 1.1 is below PQC-ready version 2.4
✗ Apache httpd PQC readiness depends on linked OpenSSL version (detected v1.0, requires >= 2.4)
80/tcp http Unknown
✓ Not a TLS or SSH service
? Apache httpd PQC readiness depends on linked OpenSSL version (version unknown)
25/tcp smtp Unknown
✓ KEM probe: not a TLS handshake record (type=32)
✓ No TLS detected (may require STARTTLS negotiation)
⚠ TLS connect failed: tls: first record does not look like a TLS handshake
22/tcp ssh OpenSSH 5.5p1 diffie-hellman-group-exchange-sha256 diffie-hellman-group-exchange-sha1 diffie-hellman-group14-sha1 diffie-hellman-group1-sha1 Not Ready
✓ SSH banner: SSH-2.0-OpenSSH_5.5p1 Debian-6+squeeze5
✓ KEX algorithms: diffie-hellman-group-exchange-sha256, diffie-hellman-group-exchange-sha1, diffie-hellman-group14-sha1, diffie-hellman-group1-sha1
✓ Host key algorithms: ssh-rsa, ssh-dss
⚠ No PQC key exchange algorithms advertised
⚠ OpenSSH 5.5p1 is below PQC-ready version 8.5
✗ OpenSSH >= 8.5 supports sntrup761x25519 PQC hybrid KEX (detected v5.0, requires >= 8.5)
Ip Base.212
MAC: 00:21:70:63:FF:35 OUI:00:21:70   OS: Windows (high)
● Risk: high 0/6 PQC ready
PortServiceProduct / Version TLS VerCipher SuiteCert TypeCert SubjectCert ExpiryCert Sig KEMSSH KEX PQC StatusNotes
139/tcp unknown Unknown
✓ Not a TLS or SSH service
135/tcp msrpc Unknown
80/tcp http Microsoft-IIS 10.0 Unknown
✓ Not a TLS or SSH service
✓ IIS/Schannel PQC support requires Windows 11 24H2+ with ML-KEM enabled
445/tcp microsoft-ds Unknown
443/tcp https HTTP 1.1 TLS 1.2 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA DV (Domain Validated) serverone.akvas.com 2024-08-11 SHA256-RSA Not Ready
✓ Cert subject: serverone.akvas.com
✓ Cert issuer: R3
✓ Cert type: DV (Domain Validated)
✓ Cert expiry: 2024-08-11
✓ Cert sig algo: SHA256-RSA
✓ KEM probe: read header: read tcp Ip Base.150:40832->Ip Base.212:443: read: connection reset by peer
⚠ Certificate uses classical signature: SHA256-RSA
✓ IIS/Schannel PQC support requires Windows 11 24H2+ with ML-KEM enabled
3389/tcp rdp Unknown
Ip Base.214 ServerTwo.hsd1.va.adamznetwork.hidden
MAC: D4:AE:52:CB:30:F5 OUI:D4:AE:52   OS: Linux/Unix (high)
● Risk: high 1/10 PQC ready
PortServiceProduct / Version TLS VerCipher SuiteCert TypeCert SubjectCert ExpiryCert Sig KEMSSH KEX PQC StatusNotes
465/tcp smtp TLS 1.3 TLS_AES_256_GCM_SHA384 Self-Signed serverthree 2027-05-30 SHA256-RSA X25519 Not Ready
✓ Cert subject: serverthree
✓ Cert issuer: serverthree
✓ Cert type: Self-Signed
✓ Cert expiry: 2027-05-30
✓ Cert sig algo: SHA256-RSA
⚠ Certificate uses classical signature: SHA256-RSA
443/tcp https HTTP 1.1 TLS 1.3 TLS_AES_128_GCM_SHA256 DV (Domain Validated) www.adamkclark.com 2026-08-10 ECDSA-SHA384 X25519 Not Ready
✓ Cert subject: www.adamkclark.com
✓ Cert issuer: E8
✓ Cert type: DV (Domain Validated)
✓ Cert expiry: 2026-08-10
✓ Cert sig algo: ECDSA-SHA384
⚠ Certificate uses classical signature: ECDSA-SHA384
⚠ HTTP 1.1 is below PQC-ready version 2.4
✗ Apache httpd PQC readiness depends on linked OpenSSL version (detected v1.0, requires >= 2.4)
143/tcp imap Unknown
✓ KEM probe: not a TLS handshake record (type=2a)
✓ No TLS detected (may require STARTTLS negotiation)
⚠ TLS connect failed: tls: first record does not look like a TLS handshake
21/tcp ftp Unknown
✓ Not a TLS or SSH service
80/tcp http Apache 2.4.66 Unknown
✓ Not a TLS or SSH service
✓ Apache httpd PQC readiness depends on linked OpenSSL version
25/tcp smtp Unknown
✓ KEM probe: not a TLS handshake record (type=32)
✓ No TLS detected (may require STARTTLS negotiation)
⚠ TLS connect failed: tls: first record does not look like a TLS handshake
9443/tcp http HTTP 1.1 TLS 1.3 TLS_AES_256_GCM_SHA384 Self-Signed serverthree 2027-05-30 SHA256-RSA X25519 Not Ready
✓ Cert subject: serverthree
✓ Cert issuer: serverthree
✓ Cert type: Self-Signed
✓ Cert expiry: 2027-05-30
✓ Cert sig algo: SHA256-RSA
⚠ Certificate uses classical signature: SHA256-RSA
9000/tcp http Unknown
✓ Not a TLS or SSH service
993/tcp imaps TLS 1.3 TLS_AES_256_GCM_SHA384 Self-Signed serverthree 2027-05-30 SHA256-RSA X25519 Not Ready
✓ Cert subject: serverthree
✓ Cert issuer: serverthree
✓ Cert type: Self-Signed
✓ Cert expiry: 2027-05-30
✓ Cert sig algo: SHA256-RSA
⚠ Certificate uses classical signature: SHA256-RSA
22/tcp ssh OpenSSH 10.2p1 mlkem768x25519-sha256 sntrup761x25519-sha512 sntrup761x25519-sha512@openssh.com curve25519-sha256 curve25519-sha256@libssh.org ecdh-sha2-nistp256 ecdh-sha2-nistp384 ecdh-sha2-nistp521 ext-info-s kex-strict-s-v00@openssh.com PQC Ready
✓ SSH banner: SSH-2.0-OpenSSH_10.2p1 Ubuntu-2ubuntu3.2
✓ KEX algorithms: mlkem768x25519-sha256, sntrup761x25519-sha512, sntrup761x25519-sha512@openssh.com, curve25519-sha256, curve25519-sha256@libssh.org, ecdh-sha2-nistp256, ecdh-sha2-nistp384, ecdh-sha2-nistp521, ext-info-s, kex-strict-s-v00@openssh.com
✓ Host key algorithms: rsa-sha2-512, rsa-sha2-256, ecdsa-sha2-nistp256, ssh-ed25519
✓ PQC KEX supported: mlkem768x25519-sha256 (ML-KEM-768 + X25519 hybrid (OpenSSH 9.9+)); sntrup761x25519-sha512@openssh.com (Streamlined NTRU + X25519 hybrid (OpenSSH 8.5+))
✓ PQC KEX is highest preference: mlkem768x25519-sha256
OpenSSH >= 8.5: sntrup761x25519 supported
OpenSSH >= 9.9: mlkem768x25519 supported
✓ OpenSSH >= 8.5 supports sntrup761x25519 PQC hybrid KEX
Ip Base.30
MAC: DA:6A:FC:E3:0E:F7 OUI:DA:6A:FC   OS: Unknown (low)
● Risk: low 0/5 PQC ready
PortServiceProduct / Version TLS VerCipher SuiteCert TypeCert SubjectCert ExpiryCert Sig KEMSSH KEX PQC StatusNotes
445/tcp microsoft-ds Unknown
53/tcp dns Unknown
139/tcp unknown Unknown
✓ Not a TLS or SSH service
135/tcp msrpc Unknown
3389/tcp rdp Unknown
MAC: FA:EB:20:C4:3A:07 OUI:FA:EB:20   OS: Unknown (low)
● Risk: high 0/11 PQC ready
PortServiceProduct / Version TLS VerCipher SuiteCert TypeCert SubjectCert ExpiryCert Sig KEMSSH KEX PQC StatusNotes
993/tcp imaps TLS 1.3 TLS_AES_256_GCM_SHA384 DV (Domain Validated) mail.adamkclark.com 2026-08-02 SHA256-RSA X25519 Not Ready
✓ Cert subject: mail.adamkclark.com
✓ Cert issuer: R12
✓ Cert type: DV (Domain Validated)
✓ Cert expiry: 2026-08-02
✓ Cert sig algo: SHA256-RSA
⚠ Certificate uses classical signature: SHA256-RSA
465/tcp smtp TLS 1.3 TLS_AES_256_GCM_SHA384 DV (Domain Validated) mail.adamkclark.com 2026-08-02 SHA256-RSA X25519 Not Ready
✓ Cert subject: mail.adamkclark.com
✓ Cert issuer: R12
✓ Cert type: DV (Domain Validated)
✓ Cert expiry: 2026-08-02
✓ Cert sig algo: SHA256-RSA
⚠ Certificate uses classical signature: SHA256-RSA
139/tcp unknown Unknown
✓ Not a TLS or SSH service
445/tcp microsoft-ds Unknown
443/tcp https HTTP 1.1 TLS 1.3 TLS_AES_256_GCM_SHA384 DV (Domain Validated) mail.adamkclark.com 2026-08-02 SHA256-RSA X25519 Not Ready
✓ Cert subject: mail.adamkclark.com
✓ Cert issuer: R12
✓ Cert type: DV (Domain Validated)
✓ Cert expiry: 2026-08-02
✓ Cert sig algo: SHA256-RSA
⚠ Certificate uses classical signature: SHA256-RSA
135/tcp msrpc Unknown
21/tcp ftp Unknown
✓ Not a TLS or SSH service
3389/tcp rdp Unknown
25/tcp smtp Unknown
✓ KEM probe: not a TLS handshake record (type=32)
✓ No TLS detected (may require STARTTLS negotiation)
⚠ TLS connect failed: tls: first record does not look like a TLS handshake
9000/tcp http Unknown
✓ Not a TLS or SSH service
9443/tcp http HTTP 1.1 TLS 1.3 TLS_AES_256_GCM_SHA384 DV (Domain Validated) mail.adamkclark.com 2025-02-22 SHA256-RSA X25519 Not Ready
✓ Cert subject: mail.adamkclark.com
✓ Cert issuer: R10
✓ Cert type: DV (Domain Validated)
✓ Cert expiry: 2025-02-22
✓ Cert sig algo: SHA256-RSA
⚠ Certificate uses classical signature: SHA256-RSA
Generated by PQScan • Post-Quantum Cryptography Network Scanner