Also useful. sslscan (http://sourceforge.net/projects/sslscan/). Point it to an endpoint and it will tell you all the ciphers and protocols that are accepted, and what the various defaults are, and details about the certificate bound to it. It's available in the Debian/Ubuntu repository for easy installation.