Page MenuHomeFreeBSD

ktls: Reject some invalid cipher suites.
ClosedPublic

Authored by jhb on Nov 5 2021, 12:04 AM.
Tags
None
Referenced Files
F157334039: D32842.id.diff
Wed, May 20, 10:12 AM
Unknown Object (File)
Tue, May 19, 4:36 AM
Unknown Object (File)
Sat, May 16, 11:59 PM
Unknown Object (File)
Thu, May 14, 1:38 PM
Unknown Object (File)
Wed, May 13, 8:32 AM
Unknown Object (File)
Wed, May 13, 1:59 AM
Unknown Object (File)
Sun, May 10, 8:13 PM
Unknown Object (File)
Wed, May 6, 1:27 AM
Subscribers

Details

Summary
  • Reject AES-CBC cipher suites for TLS 1.0 and TLS 1.1 using auth algorithms other than SHA1-HMAC.
  • Reject AES-GCM cipher suites for TLS versions older than 1.2.

Sponsored by: Netflix

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable