Page MenuHomeFreeBSD

ktls: Reject some invalid cipher suites.
ClosedPublic

Authored by jhb on Nov 5 2021, 12:04 AM.
Tags
None
Referenced Files
Unknown Object (File)
Nov 24 2024, 8:37 AM
Unknown Object (File)
Nov 23 2024, 2:35 AM
Unknown Object (File)
Nov 22 2024, 5:39 AM
Unknown Object (File)
Nov 4 2024, 4:41 AM
Unknown Object (File)
Nov 4 2024, 4:41 AM
Unknown Object (File)
Nov 4 2024, 4:21 AM
Unknown Object (File)
Oct 18 2024, 6:13 AM
Unknown Object (File)
Oct 17 2024, 10:39 PM
Subscribers

Details

Summary
  • Reject AES-CBC cipher suites for TLS 1.0 and TLS 1.1 using auth algorithms other than SHA1-HMAC.
  • Reject AES-GCM cipher suites for TLS versions older than 1.2.

Sponsored by: Netflix

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable