Page MenuHomeFreeBSD

ktls: Reject some invalid cipher suites.
ClosedPublic

Authored by jhb on Nov 5 2021, 12:04 AM.
Tags
None
Referenced Files
Unknown Object (File)
Mon, Feb 10, 11:03 AM
Unknown Object (File)
Sun, Feb 9, 4:07 AM
Unknown Object (File)
Fri, Jan 31, 7:35 PM
Unknown Object (File)
Jan 25 2025, 8:45 PM
Unknown Object (File)
Jan 20 2025, 1:57 PM
Unknown Object (File)
Jan 19 2025, 6:03 PM
Unknown Object (File)
Jan 19 2025, 5:43 PM
Unknown Object (File)
Jan 17 2025, 9:01 AM
Subscribers

Details

Summary
  • Reject AES-CBC cipher suites for TLS 1.0 and TLS 1.1 using auth algorithms other than SHA1-HMAC.
  • Reject AES-GCM cipher suites for TLS versions older than 1.2.

Sponsored by: Netflix

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable