A team from the University of Trento has developed an open-source network tool designed to prevent clients from establishing insecure Transport Layer Security (TLS) connections. Named TLSGatekeeper, the software inspects outbound TLS handshakes and enforces compliance with security guidelines without decrypting the traffic itself. The tool operates at the network level, allowing organizations to apply consistent policies across all devices—including those outside direct IT control—without requiring individual client configuration.
How TLSGatekeeper works
TLSGatekeeper functions by monitoring network traffic for TLS handshake packets. When a client initiates a connection to an external server, the tool evaluates the server-selected parameters—such as TLS version, cipher suites, and supported groups—against a predefined security policy. If the parameters violate the policy, TLSGatekeeper can either log the non-compliant connection or block it outright. Unlike traditional next-generation firewalls, which typically block only legacy TLS versions or a limited set of hardcoded ciphers, TLSGatekeeper offers full flexibility in defining undesired values and can directly implement policies from established national cybersecurity guidelines.
The tool is built using eXpress Data Path (XDP), a Linux kernel technology that allows packet processing at near line-rate speeds. By attaching directly to the network interface driver, TLSGatekeeper minimizes latency and overhead for both TLS and non-TLS traffic. Performance tests showed the tool could sustain throughput close to 100Gbps while processing thousands of handshakes per second, with inspection delays averaging 671 nanoseconds for TLS 1.3 and 795 nanoseconds for TLS 1.2 under full load.
Why compliance gaps persist
The need for TLSGatekeeper stems from a broader issue: despite the availability of national TLS guidelines from agencies like NIST, ANSSI, BSI, and ACN, real-world deployments often deviate from recommended configurations. To assess the scale of this problem, the researchers collected over 50 million TLS handshakes over a two-week period from their institution. The dataset revealed widespread use of parameters not recommended by any of the four guidelines, including insecure cipher suites and emerging post-quantum cryptography (PQC) algorithms.
One notable finding was the adoption of PQC algorithms, such as X25519MLKEM768, which appeared in nearly seven million handshakes despite not being endorsed by the guidelines at the time of the study. The researchers attributed this gap to the slow update cycles of cybersecurity agencies, which struggle to keep pace with rapid industry adoption—particularly when driven by major providers like Cloudflare and Google. The dataset also uncovered connections using Facebook’s experimental TLS 1.3 draft and other non-standard configurations, highlighting the limitations of static guidelines in addressing real-world deployments.
Background: Transport Layer Security (TLS) is the standard protocol for encrypting internet communications, but its security depends on proper configuration. National cybersecurity agencies publish guidelines to help organizations deploy TLS securely, though these recommendations often lag behind industry adoption of new algorithms and standards.
Practical implications for operators
For network administrators, TLSGatekeeper offers a scalable solution to enforce TLS policies across large, heterogeneous environments. The tool’s ability to operate at 100Gbps makes it suitable for high-speed networks, while its network-based approach eliminates the need to configure individual clients. This is particularly useful in organizations where personal devices, temporary workstations, or self-managed systems fall outside IT’s direct control.
The researchers also emphasized the potential for programmable data-plane technologies like XDP and P4 to offload security tasks from servers to the network itself. By isolating small, targeted functions—such as TLS handshake inspection—these technologies can deliver significant performance gains without compromising security or privacy.
Looking ahead, the team suggested that continuous monitoring of TLS deployments could provide better visibility into global configuration trends, helping agencies update guidelines more rapidly. They also called for faster responses from cybersecurity agencies when new standards or algorithms gain traction, particularly when adoption is driven by industry leaders.
Companies mentioned
Automated pipeline · Cloud & Infrastructure
Synthesized from 1 industry feed on 29 Sep 2026. Passed independent editor verification (score 92/100) before publication. Style guide v1.4.
Sources
Decision trail
- Checking for duplicates — Deduped batch of 2 candidates
- Checking for duplicates — New story No recent or in-pipeline article covers TLS handshake analysis or APNIC research on outbound TLS connections.
- Writing the article — Draft created article_id=619 slug=tlsgatekeeper-tool-blocks-insecure-outbound-tls-at-100gbps
-
Editor review — Approved
- Score: 92/100
- Factual grounding: The draft states 'over a two-week period' for data collection, but the source specifies 'during two weeks' without a precise date range. While the timing is plausible, the exact start/end dates are not provided in the source, so the phrasing should be adjusted to avoid implying a specific calendar window.
- Style compliance: The standfirst ('Open-source network tool enforces TLS guidelines without decrypting traffic.') is slightly redundant with the headline and could be more specific (e.g., 'Tool blocks non-compliant TLS handshakes at 100Gbps without decrypting traffic.').
- No copied phrasing: The phrase 'national cybersecurity guidelines from agencies like NIST, ANSSI, BSI, and ACN' closely mirrors the source's list ('Agenzia per la Cybersicurezza Nazionale (ACN, Italy), Agence nationale de la sécurité des systèmes d’information (ANSSI, France), Bundesamt für Sicherheit in der Informationstechnik (BSI, Germany), National Institute of Standards and Technology (NIST, United States of America)'). While the facts are correct, the phrasing should be further restructured to avoid echoing the source.
- Style compliance: The 'Background' block is well-sourced but could be tightened to 2 sentences (currently 3).
- Generating reader Q&A — Generated 5 items
- Assigning hero image — Reused library image reused image #3
- Linking related stories — Linked 4 relations from 320 candidates
- Linking related stories — Linked 4 relations from 321 candidates
- Publishing — Published tlsgatekeeper-tool-blocks-insecure-outbound-tls-at-100gbps
- Mastodon — Posted https://mstdn.social/@hostingpaper/117351886489491966




Discussion · coming soon
Be the first to join the thread when community discussion launches.