We consider the following to be the exepcted behavior:
ssl2 should not work
ssl3 should not work
tls1 should work
tls1_1 should work
tls1_2 should work
However, tls1 and tls1_1 are not insecure.. so if they don't work that's fine, but may break older client's connections.
Ports to test:
443: Apache
465: Exim
993: IMAP SSL
995: POP SSL
2222: DirectAdmin if you've got SSL enabled