Page MenuHomeFreeBSD

ktls: Reject some invalid cipher suites.
ClosedPublic

Authored by jhb on Nov 5 2021, 12:04 AM.
Tags
None
Referenced Files
F142104214: D32842.id98531.diff
Fri, Jan 16, 1:41 AM
Unknown Object (File)
Thu, Jan 8, 12:11 AM
Unknown Object (File)
Tue, Jan 6, 5:24 AM
Unknown Object (File)
Thu, Jan 1, 9:03 AM
Unknown Object (File)
Thu, Dec 18, 1:42 PM
Unknown Object (File)
Nov 27 2025, 12:31 AM
Unknown Object (File)
Nov 25 2025, 12:48 AM
Unknown Object (File)
Nov 24 2025, 11:58 AM
Subscribers

Details

Summary
  • Reject AES-CBC cipher suites for TLS 1.0 and TLS 1.1 using auth algorithms other than SHA1-HMAC.
  • Reject AES-GCM cipher suites for TLS versions older than 1.2.

Sponsored by: Netflix

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable