TLS and HTTP/3: configuration you can verify.
Reviewing HTTPS transport with negotiation evidence and external checks.
Context
Linux environments running Angie and OpenSSL requiring HTTPS transport review.
Problem
Configuration needed verification against actual behavior: certificate, protocols, stapling and cryptographic groups.
Intervention
Reviewed TLS, OCSP stapling and HSTS. Enabled HTTP/3 and tested using OpenSSL and external tools; checked X25519MLKEM768 in a compatible environment.
The procedure verifies certificates and SNI per hostname, compares negotiated protocols and checks that HTTP/2 remains available. Cryptographic-policy changes require OpenSSL and client compatibility checks plus a rollback plan.
Observed outcome
Verified OCSP stapling, HTTP/3 support and negotiation of the hybrid X25519MLKEM768 group in the tested environment.
Limits and next step
These checks are server- and date-specific. They are not a complete security audit or a guarantee of compatibility with every client.
Follow-up operations should monitor certificate renewal, OCSP responses and actual client compatibility. HSTS is expanded gradually after verifying HTTPS across covered subdomains. Modern TLS does not establish application-code security.