Page MenuHomeFreeBSD

ktls: Reject some invalid cipher suites.
ClosedPublic

Authored by jhb on Nov 5 2021, 12:04 AM.
Tags
None
Referenced Files
Unknown Object (File)
Thu, Jun 11, 5:47 PM
Unknown Object (File)
Wed, Jun 10, 12:04 AM
Unknown Object (File)
May 21 2026, 5:00 PM
Unknown Object (File)
May 20 2026, 10:12 AM
Unknown Object (File)
May 19 2026, 4:36 AM
Unknown Object (File)
May 16 2026, 11:59 PM
Unknown Object (File)
May 14 2026, 1:38 PM
Unknown Object (File)
May 13 2026, 8:32 AM
Subscribers

Details

Summary
  • Reject AES-CBC cipher suites for TLS 1.0 and TLS 1.1 using auth algorithms other than SHA1-HMAC.
  • Reject AES-GCM cipher suites for TLS versions older than 1.2.

Sponsored by: Netflix

Diff Detail

Repository
rS FreeBSD src repository - subversion
Lint
Lint Passed
Unit
No Test Coverage
Build Status
Buildable 42592
Build 39480: arc lint + arc unit