• Request consultation
  • Newsletter
  • Deutsch Deutsch German de
  • English English English en
  • Italiano Italiano Italian it
  • Nederlands Nederlands Dutch nl
Greenbone
  • Products
    • OPENVAS BASIC
      • OPENVAS BASIC: Order
    • OPENVAS SCAN
    • Upcoming Solutions
      • OPENVAS SECURITY INTELLIGENCE
      • OPENVAS AI
    • Solutions for Your Sector
      • Educational Sector
      • Healthcare Sector
      • Public Sector
    • Technology
      • Feed Comparison
      • Product Comparison
        • OPENVAS vs. Nessus
      • Roadmap & Lifecycle
  • Service & Support
    • Technical Support
    • Self-Learning Courses
    • Documents
  • Events
    • Cybersec Europe 2026
    • Webinars
  • Partners
    • MSSP
  • About Greenbone
    • Careers
    • Contact
  • Blog
    • Know-how
      • Attack Vector Timeline
      • Cyberattacks and Defense
      • Cyber Defense Security
      • Cyber Resilience Act
      • Data Security
      • Digital Operational Resilience Act
      • Exposure Management
      • IT and Information Security
      • NIS2 Directive
      • Open Source Vulnerability Management
      • The Vulnerability Timeline
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu
  • Products
    • OPENVAS BASIC
      • OPENVAS BASIC: Order
    • OPENVAS SCAN
    • Upcoming Solutions
      • OPENVAS SECURITY INTELLIGENCE
      • OPENVAS AI
    • Solutions for your sector
      • Educational Sector
      • Healthcare Sector
      • Public Sector
    • Technology
      • Feed Comparison
      • Product Comparison
        • OPENVAS vs. Nessus
      • Roadmap and Lifecycle
    • Request IT Security
  • Service & Support
    • Technical Support
    • Self-Learning Courses
    • Documents
  • Events
    • Cybersec Europe 2026
    • Webinars
  • Partners
    • MSSP
  • About Greenbone
    • Careers
    • Contact
    • Newsletter
  • Our Blog
    • Know-how
      • Attack Vector Timeline
      • Cyberattacks and Defense
      • Cyber Defense Security
      • Cyber Resilience Act
      • Data Security
      • Digital Operational Resilience Act
      • Exposure Management
      • IT and Information Security
      • NIS2 Directive
      • Open Source Vulnerability Management
      • The Vulnerability Timeline
  • German
  • English
  • Italian
  • Dutch
Greenbone AG

TLS and SSH Security: Greenbone Has Updated Compliance Policies for the BSI’s TR-03116-4 and TR-02102-4

Blog

Glowing green atom illustration with the label 'BSI-Ready TLS & SSH' on a dark green background

Technical guidelines published by government bodies define the highest security standards for protecting the national IT infrastructure. As the cyber security landscape becomes more perilous, it’s even more important for organizations to be diligent about implementing the strictest security standards. Government organizations need to ensure compliance, while private-sector entities can use the standards as benchmarks for their own cyber resilience.

Greenbone is happy to announce updated compliance scans aligned with the German Federal Office for Information Security’s (BSI) minimum standards for hardening TLS and SSH. The policies identify specific TLS and SSH configuration gaps within portions of the respective guidance.

In this article, we review the TR-03116-4 and TR-02102-4 guidelines to understand what’s new. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way for your organization to gain the deepest insight into building resilient IT networks and applications.

The Transport Layer Security (TLS) and Secure Shell (SSH) protocols are among the most fundamental used in today’s networks. Greenbone now offers updated policy scans to measure compliance with selected portions of the BSI’s guidance. The updated guidance standards are:

  • TR-03116-4 (July 2025): BSI Minimum Standard for the Use of Transport Layer Security (TLS)
  • TR-02102-4 (January 2026): BSI Minimum Standard for the Use of Secure Shell (SSH)

These updates add to Greenbone’s already impressive line of compliance policies for OPENVAS SCAN. Although TR-03116-4 and TR-02102-4 do not yet include post-quantum cryptography guidelines, standards for assessing PQC-compliant systems are under development. Greenbone has helped lead the way. Our OPENVAS ENTERPRISE FEED features PQC compliance scans for both TLS and SSH:

  • SSL/TLS: Post Quantum Cryptography (PQC) Policy Check
  • SSH: Post Quantum Cryptography (PQC) Policy Check

Comparison of Greenbone’s new BSI compliance checks for TLS and SSH

TLS
TR-03116-4
BSI TLS Minimum Standard · July 2025
  • ✓Supported and minimum allowed TLS versions
  • ✓TLS 1.2 / 1.3 cipher suites vs. policy allow lists
  • ✓At least one BSI-mandated cipher suite supported
SSH
TR-02102-4
BSI SSH Minimum Standard · January 2026
  • ✓Protocol version, key-exchange, encryption, MAC, host-key algorithms, rekey limit
  • ✓AuthenticationMethods / RequiredAuthentications and PubkeyAuthentication
Neither standard defines PQC compliance yet — both advise starting a hybrid classical + quantum-safe migration now. Greenbone offers separate SSL/TLS PQC and SSH PQC policy checks.

Understanding TR-03116-4 BSI Minimum Standards for the Use of TLS

Part 4 of the TR-03116 series of technical guidelines specifies requirements and recommendations for the use of TLS in federal government applications. TR-03116-4 builds on earlier releases in the series. The standard is generally valid until the end of 2030, although specific timelines for deprecating or implementing certain methods are included. Greenbone’s policy covers selected portions of TR-03116-4; using remote TLS handshakes, the compliance scan assesses selected Chapter 2 controls, including:

  • Supported and minimum allowed TLS versions
  • Configured TLS 1.2 and TLS 1.3 cipher suites against policy allow lists
  • Presence of at least one BSI-mandated cipher suite supported by the server

Other vulnerability tests in the OPENVAS ENTERPRISE FEED separately identify additional risks posed by the remaining guidance areas. Examples include known SAML authentication and XML-signature vulnerabilities, vulnerable S/MIME/CMS implementations in OpenSSL or mail products, and OpenPGP/PGP software detection and product vulnerabilities.

Understanding TR-02102-4 BSI Minimum Standards for the Use of SSH

Part 4 of the BSI’s TR-02102 guideline series specifies the recommended SSH protocol versions, cryptographic algorithms, and key lengths for use in federal government applications. Like TR-03116-4 described above, TR-02102-4 builds on earlier guidance in its series, specifically TR-02102-1.

The Greenbone’s new compliance scans verify selected values read from the SSH server configuration, including:

  • SSH protocol version, allowed key-exchanges, encryption algorithms, MAC, host-key algorithms, and rekey limit
  • Client authentication requirements through AuthenticationMethods or RequiredAuthentications, and PubkeyAuthentication

These authenticated configuration checks provide useful technical evidence, but do not test live authentication behavior or assess client application risks, side channel attacks, implementation flaws, or operational controls associated with all SSH use-cases.

Post Quantum Compliance with Greenbone

Neither TR-03116-4 nor TR-02102-4 define compliance standards for Post Quantum Cryptography (PQC). However, they advise that organizations should prepare now to migrate from classical asymmetric cryptography to quantum-safe cryptography, beginning with hybrid schemes that combine classical and quantum-safe algorithms. Organizations seeking to assess their PQC resilience today can use Greenbone’s existing PQC policy scans:

  • SSL/TLS: Post Quantum Cryptography (PQC) Policy Check
  • SSH: Post Quantum Cryptography (PQC) Policy Check

Get to Know Greenbone’s Full Suite of Compliance Scans

OPENVAS SCAN’s compliance policies consist of specially selected groups of vulnerability tests used to assess compliance. Whether your organization is required to meet BSI technical standards or you simply want deeper insight into building resilient IT networks and applications, OPENVAS SCAN provides compliance visibility to identify gaps and strengthen security.

Some of the compliance scans in Greenbone’s OPENVAS ENTERPRISE FEED:

  • CIS Benchmark for Microsoft SQL Server 2022
  • CIS Benchmark v5.0.0 for Microsoft Windows Server 2022
  • CIS Benchmark v2.0.0 for Microsoft Windows Server 2025
  • CIS Benchmark v1.10 for Kubernetes 1.28 Controller Node
  • CIS Benchmark v1.10 for Kubernetes 1.28 Worker Nodes
  • Compliance profiles for Huawei EulerOS, openEuler, and Huawei Cloud EulerOS
  • CIS Benchmark v3.0.0 (L1) for Microsoft Windows 11 Enterprise
  • CIS Benchmarks v3.0.0 (L1 – Windows) for Google Chrome
  • BSI and CIS Benchmarks for Microsoft Office
  • Policy check for SSH: Post Quantum Cryptography (PQC)
  • Policy check for SSL/TLS: Post Quantum Cryptography (PQC)

Need compliance visibility into your TLS and SSH configurations?

Whether your organization is required to meet BSI technical standards or you simply want deeper insight into building resilient IT networks and applications, OPENVAS SCAN provides the compliance visibility needed to identify gaps and strengthen security. Contact Greenbone’s sales team to discuss how compliance scanning can best fit your organization’s regulatory and security governance requirements.

➤ Contact Sales

Summary

Germany’s BSI sets the technical requirements for federal government IT infrastructure. Other national governments around the world publish their own security forecasts and guidelines. While private institutions are not typically required to implement these guidelines, they offer reliable insight for implementing resilient IT architecture.

The Transport Layer Security (TLS) and Secure Shell (SSH) are two of the most fundamental protocols used in today’s IT networks. Greenbone is happy to announce updated compliance scans for selected portions of the BSI’s minimum standards for hardening TLS and SSH according to TR-03116-4 and TR-02102-4. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way for your organization to gain the deepest insight into building resilient IT networks and applications.

 

Contact Test Now Buy Here Back to Overview
21. July 2026/by Greenbone AG
Share this entry
  • Share on LinkedIn
  • Share by Mail
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Greenbone AG https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Greenbone AG2026-07-21 13:49:062026-07-21 13:49:06TLS and SSH Security: Greenbone Has Updated Compliance Policies for the BSI’s TR-03116-4 and TR-02102-4

Search

Search Search

Archive

  • 2026
  • 2025

Newsletter

Subscribe Now

OPENVAS BASIC

Our entry-level enterprise product

Test 14 Days Free of Charge

Products & Solutions

  • OPENVAS PRODUCTS
  • OPENVAS SECURITY INTELLIGENCE
  • OPENVAS SCAN
  • OPENVAS BASIC
  • OPENVAS FREE
  • OPENVAS AI
ISO9001-EN

Service & Support

  • Technical Support
  • FAQ
  • Documents
  • Warranty
  • Open Source Vulnerability Management
  • Cyber Resilience Act
ISO27001-EN

About us

  • About Greenbone
  • Partners
  • MSSP
  • License information
  • Privacy Statement
  • Terms & Conditions
ISO14001-EN

Contact with us

  • Contact
  • Newsletter
  • Media Contact
  • Careers
  • Security Response
  • Imprint
  • Grounding Page

Community

  • Community Portal
  • Community Forum
© Copyright - Greenbone AG 2020-2026
  • Link to LinkedIn
Link to: Greenbone’s OPENVAS SCAN Now Supports the Nutanix AHV Hypervisor Link to: Greenbone’s OPENVAS SCAN Now Supports the Nutanix AHV Hypervisor Greenbone’s OPENVAS SCAN Now Supports the Nutanix AHV Hypervisor
Scroll to top Scroll to top Scroll to top
Contact
Request IT Security Contact Us Subscribe to Newsletter Follow on LinkedIn