TLS and SSH Security: Greenbone Has Updated Compliance Policies for the BSI’s TR-03116-4 and TR-02102-4

Technical guidelines published by government bodies define the highest security standards for protecting the national IT infrastructure. As the cyber security landscape becomes more perilous, it’s even more important for organizations to be diligent about implementing the strictest security standards. Government organizations need to ensure compliance, while private-sector entities can use the standards as benchmarks for their own cyber resilience.
Greenbone is happy to announce updated compliance scans aligned with the German Federal Office for Information Security’s (BSI) minimum standards for hardening TLS and SSH. The policies identify specific TLS and SSH configuration gaps within portions of the respective guidance.
In this article, we review the TR-03116-4 and TR-02102-4 guidelines to understand what’s new. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way for your organization to gain the deepest insight into building resilient IT networks and applications.
The Transport Layer Security (TLS) and Secure Shell (SSH) protocols are among the most fundamental used in today’s networks. Greenbone now offers updated policy scans to measure compliance with selected portions of the BSI’s guidance. The updated guidance standards are:
- TR-03116-4 (July 2025): BSI Minimum Standard for the Use of Transport Layer Security (TLS)
- TR-02102-4 (January 2026): BSI Minimum Standard for the Use of Secure Shell (SSH)
These updates add to Greenbone’s already impressive line of compliance policies for OPENVAS SCAN. Although TR-03116-4 and TR-02102-4 do not yet include post-quantum cryptography guidelines, standards for assessing PQC-compliant systems are under development. Greenbone has helped lead the way. Our OPENVAS ENTERPRISE FEED features PQC compliance scans for both TLS and SSH:
- SSL/TLS: Post Quantum Cryptography (PQC) Policy Check
- SSH: Post Quantum Cryptography (PQC) Policy Check
Comparison of Greenbone’s new BSI compliance checks for TLS and SSH
- ✓Supported and minimum allowed TLS versions
- ✓TLS 1.2 / 1.3 cipher suites vs. policy allow lists
- ✓At least one BSI-mandated cipher suite supported
- ✓Protocol version, key-exchange, encryption, MAC, host-key algorithms, rekey limit
- ✓AuthenticationMethods / RequiredAuthentications and PubkeyAuthentication
Understanding TR-03116-4 BSI Minimum Standards for the Use of TLS
Part 4 of the TR-03116 series of technical guidelines specifies requirements and recommendations for the use of TLS in federal government applications. TR-03116-4 builds on earlier releases in the series. The standard is generally valid until the end of 2030, although specific timelines for deprecating or implementing certain methods are included. Greenbone’s policy covers selected portions of TR-03116-4; using remote TLS handshakes, the compliance scan assesses selected Chapter 2 controls, including:
- Supported and minimum allowed TLS versions
- Configured TLS 1.2 and TLS 1.3 cipher suites against policy allow lists
- Presence of at least one BSI-mandated cipher suite supported by the server
Other vulnerability tests in the OPENVAS ENTERPRISE FEED separately identify additional risks posed by the remaining guidance areas. Examples include known SAML authentication and XML-signature vulnerabilities, vulnerable S/MIME/CMS implementations in OpenSSL or mail products, and OpenPGP/PGP software detection and product vulnerabilities.
Understanding TR-02102-4 BSI Minimum Standards for the Use of SSH
Part 4 of the BSI’s TR-02102 guideline series specifies the recommended SSH protocol versions, cryptographic algorithms, and key lengths for use in federal government applications. Like TR-03116-4 described above, TR-02102-4 builds on earlier guidance in its series, specifically TR-02102-1.
The Greenbone’s new compliance scans verify selected values read from the SSH server configuration, including:
- SSH protocol version, allowed key-exchanges, encryption algorithms, MAC, host-key algorithms, and rekey limit
- Client authentication requirements through AuthenticationMethods or RequiredAuthentications, and PubkeyAuthentication
These authenticated configuration checks provide useful technical evidence, but do not test live authentication behavior or assess client application risks, side channel attacks, implementation flaws, or operational controls associated with all SSH use-cases.
Post Quantum Compliance with Greenbone
Neither TR-03116-4 nor TR-02102-4 define compliance standards for Post Quantum Cryptography (PQC). However, they advise that organizations should prepare now to migrate from classical asymmetric cryptography to quantum-safe cryptography, beginning with hybrid schemes that combine classical and quantum-safe algorithms. Organizations seeking to assess their PQC resilience today can use Greenbone’s existing PQC policy scans:
- SSL/TLS: Post Quantum Cryptography (PQC) Policy Check
- SSH: Post Quantum Cryptography (PQC) Policy Check
Get to Know Greenbone’s Full Suite of Compliance Scans
OPENVAS SCAN’s compliance policies consist of specially selected groups of vulnerability tests used to assess compliance. Whether your organization is required to meet BSI technical standards or you simply want deeper insight into building resilient IT networks and applications, OPENVAS SCAN provides compliance visibility to identify gaps and strengthen security.
Some of the compliance scans in Greenbone’s OPENVAS ENTERPRISE FEED:
- CIS Benchmark for Microsoft SQL Server 2022
- CIS Benchmark v5.0.0 for Microsoft Windows Server 2022
- CIS Benchmark v2.0.0 for Microsoft Windows Server 2025
- CIS Benchmark v1.10 for Kubernetes 1.28 Controller Node
- CIS Benchmark v1.10 for Kubernetes 1.28 Worker Nodes
- Compliance profiles for Huawei EulerOS, openEuler, and Huawei Cloud EulerOS
- CIS Benchmark v3.0.0 (L1) for Microsoft Windows 11 Enterprise
- CIS Benchmarks v3.0.0 (L1 – Windows) for Google Chrome
- BSI and CIS Benchmarks for Microsoft Office
- Policy check for SSH: Post Quantum Cryptography (PQC)
- Policy check for SSL/TLS: Post Quantum Cryptography (PQC)
Need compliance visibility into your TLS and SSH configurations?
Whether your organization is required to meet BSI technical standards or you simply want deeper insight into building resilient IT networks and applications, OPENVAS SCAN provides the compliance visibility needed to identify gaps and strengthen security. Contact Greenbone’s sales team to discuss how compliance scanning can best fit your organization’s regulatory and security governance requirements.
Summary
Germany’s BSI sets the technical requirements for federal government IT infrastructure. Other national governments around the world publish their own security forecasts and guidelines. While private institutions are not typically required to implement these guidelines, they offer reliable insight for implementing resilient IT architecture.
The Transport Layer Security (TLS) and Secure Shell (SSH) are two of the most fundamental protocols used in today’s IT networks. Greenbone is happy to announce updated compliance scans for selected portions of the BSI’s minimum standards for hardening TLS and SSH according to TR-03116-4 and TR-02102-4. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way for your organization to gain the deepest insight into building resilient IT networks and applications.



