< prev index next >

src/share/classes/sun/security/ssl/CipherSuite.java

Print this page
rev 14340 : 8234728: Some security tests should support TLSv1.3
Summary: Tests were updated to support TLSv1.3 and cipher suite order
Reviewed-by: xuelei


 371             K_ECDH_ECDSA, B_RC4_128, M_SHA, H_SHA256),
 372     TLS_ECDH_RSA_WITH_RC4_128_SHA(
 373             0xC00C, false, "TLS_ECDH_RSA_WITH_RC4_128_SHA", "",
 374             ProtocolVersion.PROTOCOLS_TO_TLS12,
 375             K_ECDH_RSA, B_RC4_128, M_SHA, H_SHA256),
 376     SSL_RSA_WITH_RC4_128_MD5(
 377             0x0004, false, "SSL_RSA_WITH_RC4_128_MD5",
 378                            "TLS_RSA_WITH_RC4_128_MD5",
 379             ProtocolVersion.PROTOCOLS_TO_TLS12,
 380             K_RSA, B_RC4_128, M_MD5, H_SHA256),
 381     TLS_ECDH_anon_WITH_RC4_128_SHA(
 382             0xC016, false, "TLS_ECDH_anon_WITH_RC4_128_SHA", "",
 383             ProtocolVersion.PROTOCOLS_TO_TLS12,
 384             K_ECDH_ANON, B_RC4_128, M_SHA, H_SHA256),
 385     SSL_DH_anon_WITH_RC4_128_MD5(
 386             0x0018, false, "SSL_DH_anon_WITH_RC4_128_MD5",
 387                            "TLS_DH_anon_WITH_RC4_128_MD5",
 388             ProtocolVersion.PROTOCOLS_TO_TLS12,
 389             K_DH_ANON, B_RC4_128, M_MD5, H_SHA256),
 390 
 391     // weak cipher suites obsoleted in TLS 1.2 [RFC 5246]
 392     SSL_RSA_WITH_DES_CBC_SHA(
 393             0x0009, false, "SSL_RSA_WITH_DES_CBC_SHA",
 394                            "TLS_RSA_WITH_DES_CBC_SHA",
 395             ProtocolVersion.PROTOCOLS_TO_11,
 396             K_RSA, B_DES, M_SHA, H_NONE),
 397     SSL_DHE_RSA_WITH_DES_CBC_SHA(
 398             0x0015, false, "SSL_DHE_RSA_WITH_DES_CBC_SHA",
 399                            "TLS_DHE_RSA_WITH_DES_CBC_SHA",
 400             ProtocolVersion.PROTOCOLS_TO_11,
 401             K_DHE_RSA, B_DES, M_SHA, H_NONE),
 402     SSL_DHE_DSS_WITH_DES_CBC_SHA(
 403             0x0012, false, "SSL_DHE_DSS_WITH_DES_CBC_SHA",
 404                            "TLS_DHE_DSS_WITH_DES_CBC_SHA",
 405             ProtocolVersion.PROTOCOLS_TO_11,
 406             K_DHE_DSS, B_DES, M_SHA, H_NONE),
 407     SSL_DH_anon_WITH_DES_CBC_SHA(
 408             0x001A, false, "SSL_DH_anon_WITH_DES_CBC_SHA",
 409                            "TLS_DH_anon_WITH_DES_CBC_SHA",
 410             ProtocolVersion.PROTOCOLS_TO_11,
 411             K_DH_ANON, B_DES, M_SHA, H_NONE),
 412 
 413     // weak cipher suites obsoleted in TLS 1.1  [RFC 4346]
 414     SSL_RSA_EXPORT_WITH_DES40_CBC_SHA(
 415             0x0008, false, "SSL_RSA_EXPORT_WITH_DES40_CBC_SHA",
 416                            "TLS_RSA_EXPORT_WITH_DES40_CBC_SHA",
 417             ProtocolVersion.PROTOCOLS_TO_10,
 418             K_RSA_EXPORT, B_DES_40, M_SHA, H_NONE),
 419     SSL_DHE_RSA_EXPORT_WITH_DES40_CBC_SHA(
 420             0x0014, false, "SSL_DHE_RSA_EXPORT_WITH_DES40_CBC_SHA",
 421                            "TLS_DHE_RSA_EXPORT_WITH_DES40_CBC_SHA",
 422             ProtocolVersion.PROTOCOLS_TO_10,
 423             K_DHE_RSA_EXPORT, B_DES_40, M_SHA, H_NONE),
 424     SSL_DHE_DSS_EXPORT_WITH_DES40_CBC_SHA(
 425             0x0011, false, "SSL_DHE_DSS_EXPORT_WITH_DES40_CBC_SHA",
 426                            "TLS_DHE_DSS_EXPORT_WITH_DES40_CBC_SHA",
 427             ProtocolVersion.PROTOCOLS_TO_10,
 428             K_DHE_DSS_EXPORT, B_DES_40, M_SHA, H_NONE),
 429     SSL_DH_anon_EXPORT_WITH_DES40_CBC_SHA(
 430             0x0019, false, "SSL_DH_anon_EXPORT_WITH_DES40_CBC_SHA",
 431                            "TLS_DH_anon_EXPORT_WITH_DES40_CBC_SHA",
 432             ProtocolVersion.PROTOCOLS_TO_10,
 433             K_DH_ANON_EXPORT, B_DES_40, M_SHA, H_NONE),
 434     SSL_RSA_EXPORT_WITH_RC4_40_MD5(
 435             0x0003, false, "SSL_RSA_EXPORT_WITH_RC4_40_MD5",
 436                            "TLS_RSA_EXPORT_WITH_RC4_40_MD5",
 437             ProtocolVersion.PROTOCOLS_TO_10,
 438             K_RSA_EXPORT, B_RC4_40, M_MD5, H_NONE),
 439     SSL_DH_anon_EXPORT_WITH_RC4_40_MD5(
 440             0x0017, false, "SSL_DH_anon_EXPORT_WITH_RC4_40_MD5",
 441                            "TLS_DH_anon_EXPORT_WITH_RC4_40_MD5",
 442             ProtocolVersion.PROTOCOLS_TO_10,
 443             K_DH_ANON, B_RC4_40, M_MD5, H_NONE),
 444 
 445     // no traffic encryption cipher suites
 446     TLS_RSA_WITH_NULL_SHA256(
 447             0x003B, false, "TLS_RSA_WITH_NULL_SHA256", "",
 448             ProtocolVersion.PROTOCOLS_OF_12,
 449             K_RSA, B_NULL, M_SHA256, H_SHA256),
 450     TLS_ECDHE_ECDSA_WITH_NULL_SHA(
 451             0xC006, false, "TLS_ECDHE_ECDSA_WITH_NULL_SHA", "",
 452             ProtocolVersion.PROTOCOLS_TO_12,
 453             K_ECDHE_ECDSA, B_NULL, M_SHA, H_SHA256),
 454     TLS_ECDHE_RSA_WITH_NULL_SHA(
 455             0xC010, false, "TLS_ECDHE_RSA_WITH_NULL_SHA", "",
 456             ProtocolVersion.PROTOCOLS_TO_12,
 457             K_ECDHE_RSA, B_NULL, M_SHA, H_SHA256),
 458     SSL_RSA_WITH_NULL_SHA(
 459             0x0002, false, "SSL_RSA_WITH_NULL_SHA",
 460                            "TLS_RSA_WITH_NULL_SHA",
 461             ProtocolVersion.PROTOCOLS_TO_12,
 462             K_RSA, B_NULL, M_SHA, H_SHA256),
 463     TLS_ECDH_ECDSA_WITH_NULL_SHA(
 464             0xC001, false, "TLS_ECDH_ECDSA_WITH_NULL_SHA", "",
 465             ProtocolVersion.PROTOCOLS_TO_12,


 504             0x0022, false, "TLS_KRB5_WITH_DES_CBC_MD5", "",
 505             ProtocolVersion.PROTOCOLS_TO_11,
 506             K_KRB5, B_DES, M_MD5, H_SHA256),
 507     TLS_KRB5_EXPORT_WITH_DES_CBC_40_SHA(
 508             0x0026, false, "TLS_KRB5_EXPORT_WITH_DES_CBC_40_SHA", "",
 509             ProtocolVersion.PROTOCOLS_TO_10,
 510             K_KRB5_EXPORT, B_DES_40, M_SHA, H_SHA256),
 511     TLS_KRB5_EXPORT_WITH_DES_CBC_40_MD5(
 512             0x0029, false, "TLS_KRB5_EXPORT_WITH_DES_CBC_40_MD5", "",
 513             ProtocolVersion.PROTOCOLS_TO_10,
 514             K_KRB5_EXPORT, B_DES_40, M_MD5, H_SHA256),
 515     TLS_KRB5_EXPORT_WITH_RC4_40_SHA(
 516             0x0028, false, "TLS_KRB5_EXPORT_WITH_RC4_40_SHA", "",
 517             ProtocolVersion.PROTOCOLS_TO_10,
 518             K_KRB5_EXPORT, B_RC4_40, M_SHA, H_SHA256),
 519     TLS_KRB5_EXPORT_WITH_RC4_40_MD5(
 520             0x002B, false, "TLS_KRB5_EXPORT_WITH_RC4_40_MD5", "",
 521             ProtocolVersion.PROTOCOLS_TO_10,
 522             K_KRB5_EXPORT, B_RC4_40, M_MD5, H_SHA256),
 523 
 524     // Definition of the CipherSuites that are not supported but the names
 525     // are known.
 526     TLS_CHACHA20_POLY1305_SHA256(                    // TLS 1.3
 527             "TLS_CHACHA20_POLY1305_SHA256", 0x1303),
 528     TLS_AES_128_CCM_SHA256(                          // TLS 1.3
 529             "TLS_AES_128_CCM_SHA256", 0x1304),
 530     TLS_AES_128_CCM_8_SHA256(                        // TLS 1.3
 531             "TLS_AES_128_CCM_8_SHA256", 0x1305),
 532 
 533     // remaining unsupported ciphersuites defined in RFC2246.
 534     CS_0006("SSL_RSA_EXPORT_WITH_RC2_CBC_40_MD5",           0x0006),
 535     CS_0007("SSL_RSA_WITH_IDEA_CBC_SHA",                    0x0007),
 536     CS_000B("SSL_DH_DSS_EXPORT_WITH_DES40_CBC_SHA",         0x000b),
 537     CS_000C("SSL_DH_DSS_WITH_DES_CBC_SHA",                  0x000c),
 538     CS_000D("SSL_DH_DSS_WITH_3DES_EDE_CBC_SHA",             0x000d),
 539     CS_000E("SSL_DH_RSA_EXPORT_WITH_DES40_CBC_SHA",         0x000e),
 540     CS_000F("SSL_DH_RSA_WITH_DES_CBC_SHA",                  0x000f),
 541     CS_0010("SSL_DH_RSA_WITH_3DES_EDE_CBC_SHA",             0x0010),
 542 
 543     // SSL 3.0 Fortezza ciphersuites
 544     CS_001C("SSL_FORTEZZA_DMS_WITH_NULL_SHA",               0x001c),
 545     CS_001D("SSL_FORTEZZA_DMS_WITH_FORTEZZA_CBC_SHA",       0x001d),
 546 
 547     // 1024/56 bit exportable ciphersuites from expired internet draft
 548     CS_0062("SSL_RSA_EXPORT1024_WITH_DES_CBC_SHA",          0x0062),
 549     CS_0063("SSL_DHE_DSS_EXPORT1024_WITH_DES_CBC_SHA",      0x0063),
 550     CS_0064("SSL_RSA_EXPORT1024_WITH_RC4_56_SHA",           0x0064),
 551     CS_0065("SSL_DHE_DSS_EXPORT1024_WITH_RC4_56_SHA",       0x0065),
 552     CS_0066("SSL_DHE_DSS_WITH_RC4_128_SHA",                 0x0066),
 553 
 554     // Netscape old and new SSL 3.0 FIPS ciphersuites
 555     // see http://www.mozilla.org/projects/security/pki/nss/ssl/fips-ssl-ciphersuites.html
 556     CS_FFE0("NETSCAPE_RSA_FIPS_WITH_3DES_EDE_CBC_SHA",      0xffe0),
 557     CS_FFE1("NETSCAPE_RSA_FIPS_WITH_DES_CBC_SHA",           0xffe1),
 558     CS_FEFE("SSL_RSA_FIPS_WITH_DES_CBC_SHA",                0xfefe),
 559     CS_FEFF("SSL_RSA_FIPS_WITH_3DES_EDE_CBC_SHA",           0xfeff),
 560 
 561     // Unsupported Kerberos cipher suites from RFC 2712
 562     CS_0021("TLS_KRB5_WITH_IDEA_CBC_SHA",                   0x0021),
 563     CS_0025("TLS_KRB5_WITH_IDEA_CBC_MD5",                   0x0025),
 564     CS_0027("TLS_KRB5_EXPORT_WITH_RC2_CBC_40_SHA",          0x0027),
 565     CS_002A("TLS_KRB5_EXPORT_WITH_RC2_CBC_40_MD5",          0x002a),
 566 
 567     // Unsupported cipher suites from RFC 4162
 568     CS_0096("TLS_RSA_WITH_SEED_CBC_SHA",                    0x0096),
 569     CS_0097("TLS_DH_DSS_WITH_SEED_CBC_SHA",                 0x0097),
 570     CS_0098("TLS_DH_RSA_WITH_SEED_CBC_SHA",                 0x0098),
 571     CS_0099("TLS_DHE_DSS_WITH_SEED_CBC_SHA",                0x0099),
 572     CS_009A("TLS_DHE_RSA_WITH_SEED_CBC_SHA",                0x009a),
 573     CS_009B("TLS_DH_anon_WITH_SEED_CBC_SHA",                0x009b),
 574 




 371             K_ECDH_ECDSA, B_RC4_128, M_SHA, H_SHA256),
 372     TLS_ECDH_RSA_WITH_RC4_128_SHA(
 373             0xC00C, false, "TLS_ECDH_RSA_WITH_RC4_128_SHA", "",
 374             ProtocolVersion.PROTOCOLS_TO_TLS12,
 375             K_ECDH_RSA, B_RC4_128, M_SHA, H_SHA256),
 376     SSL_RSA_WITH_RC4_128_MD5(
 377             0x0004, false, "SSL_RSA_WITH_RC4_128_MD5",
 378                            "TLS_RSA_WITH_RC4_128_MD5",
 379             ProtocolVersion.PROTOCOLS_TO_TLS12,
 380             K_RSA, B_RC4_128, M_MD5, H_SHA256),
 381     TLS_ECDH_anon_WITH_RC4_128_SHA(
 382             0xC016, false, "TLS_ECDH_anon_WITH_RC4_128_SHA", "",
 383             ProtocolVersion.PROTOCOLS_TO_TLS12,
 384             K_ECDH_ANON, B_RC4_128, M_SHA, H_SHA256),
 385     SSL_DH_anon_WITH_RC4_128_MD5(
 386             0x0018, false, "SSL_DH_anon_WITH_RC4_128_MD5",
 387                            "TLS_DH_anon_WITH_RC4_128_MD5",
 388             ProtocolVersion.PROTOCOLS_TO_TLS12,
 389             K_DH_ANON, B_RC4_128, M_MD5, H_SHA256),
 390 
 391     // Weak cipher suites obsoleted in TLS 1.2 [RFC 5246]
 392     SSL_RSA_WITH_DES_CBC_SHA(
 393             0x0009, false, "SSL_RSA_WITH_DES_CBC_SHA",
 394                            "TLS_RSA_WITH_DES_CBC_SHA",
 395             ProtocolVersion.PROTOCOLS_TO_11,
 396             K_RSA, B_DES, M_SHA, H_NONE),
 397     SSL_DHE_RSA_WITH_DES_CBC_SHA(
 398             0x0015, false, "SSL_DHE_RSA_WITH_DES_CBC_SHA",
 399                            "TLS_DHE_RSA_WITH_DES_CBC_SHA",
 400             ProtocolVersion.PROTOCOLS_TO_11,
 401             K_DHE_RSA, B_DES, M_SHA, H_NONE),
 402     SSL_DHE_DSS_WITH_DES_CBC_SHA(
 403             0x0012, false, "SSL_DHE_DSS_WITH_DES_CBC_SHA",
 404                            "TLS_DHE_DSS_WITH_DES_CBC_SHA",
 405             ProtocolVersion.PROTOCOLS_TO_11,
 406             K_DHE_DSS, B_DES, M_SHA, H_NONE),
 407     SSL_DH_anon_WITH_DES_CBC_SHA(
 408             0x001A, false, "SSL_DH_anon_WITH_DES_CBC_SHA",
 409                            "TLS_DH_anon_WITH_DES_CBC_SHA",
 410             ProtocolVersion.PROTOCOLS_TO_11,
 411             K_DH_ANON, B_DES, M_SHA, H_NONE),
 412 
 413     // Weak cipher suites obsoleted in TLS 1.1  [RFC 4346]
 414     SSL_RSA_EXPORT_WITH_DES40_CBC_SHA(
 415             0x0008, false, "SSL_RSA_EXPORT_WITH_DES40_CBC_SHA",
 416                            "TLS_RSA_EXPORT_WITH_DES40_CBC_SHA",
 417             ProtocolVersion.PROTOCOLS_TO_10,
 418             K_RSA_EXPORT, B_DES_40, M_SHA, H_NONE),
 419     SSL_DHE_RSA_EXPORT_WITH_DES40_CBC_SHA(
 420             0x0014, false, "SSL_DHE_RSA_EXPORT_WITH_DES40_CBC_SHA",
 421                            "TLS_DHE_RSA_EXPORT_WITH_DES40_CBC_SHA",
 422             ProtocolVersion.PROTOCOLS_TO_10,
 423             K_DHE_RSA_EXPORT, B_DES_40, M_SHA, H_NONE),
 424     SSL_DHE_DSS_EXPORT_WITH_DES40_CBC_SHA(
 425             0x0011, false, "SSL_DHE_DSS_EXPORT_WITH_DES40_CBC_SHA",
 426                            "TLS_DHE_DSS_EXPORT_WITH_DES40_CBC_SHA",
 427             ProtocolVersion.PROTOCOLS_TO_10,
 428             K_DHE_DSS_EXPORT, B_DES_40, M_SHA, H_NONE),
 429     SSL_DH_anon_EXPORT_WITH_DES40_CBC_SHA(
 430             0x0019, false, "SSL_DH_anon_EXPORT_WITH_DES40_CBC_SHA",
 431                            "TLS_DH_anon_EXPORT_WITH_DES40_CBC_SHA",
 432             ProtocolVersion.PROTOCOLS_TO_10,
 433             K_DH_ANON_EXPORT, B_DES_40, M_SHA, H_NONE),
 434     SSL_RSA_EXPORT_WITH_RC4_40_MD5(
 435             0x0003, false, "SSL_RSA_EXPORT_WITH_RC4_40_MD5",
 436                            "TLS_RSA_EXPORT_WITH_RC4_40_MD5",
 437             ProtocolVersion.PROTOCOLS_TO_10,
 438             K_RSA_EXPORT, B_RC4_40, M_MD5, H_NONE),
 439     SSL_DH_anon_EXPORT_WITH_RC4_40_MD5(
 440             0x0017, false, "SSL_DH_anon_EXPORT_WITH_RC4_40_MD5",
 441                            "TLS_DH_anon_EXPORT_WITH_RC4_40_MD5",
 442             ProtocolVersion.PROTOCOLS_TO_10,
 443             K_DH_ANON, B_RC4_40, M_MD5, H_NONE),
 444 
 445     // No traffic encryption cipher suites
 446     TLS_RSA_WITH_NULL_SHA256(
 447             0x003B, false, "TLS_RSA_WITH_NULL_SHA256", "",
 448             ProtocolVersion.PROTOCOLS_OF_12,
 449             K_RSA, B_NULL, M_SHA256, H_SHA256),
 450     TLS_ECDHE_ECDSA_WITH_NULL_SHA(
 451             0xC006, false, "TLS_ECDHE_ECDSA_WITH_NULL_SHA", "",
 452             ProtocolVersion.PROTOCOLS_TO_12,
 453             K_ECDHE_ECDSA, B_NULL, M_SHA, H_SHA256),
 454     TLS_ECDHE_RSA_WITH_NULL_SHA(
 455             0xC010, false, "TLS_ECDHE_RSA_WITH_NULL_SHA", "",
 456             ProtocolVersion.PROTOCOLS_TO_12,
 457             K_ECDHE_RSA, B_NULL, M_SHA, H_SHA256),
 458     SSL_RSA_WITH_NULL_SHA(
 459             0x0002, false, "SSL_RSA_WITH_NULL_SHA",
 460                            "TLS_RSA_WITH_NULL_SHA",
 461             ProtocolVersion.PROTOCOLS_TO_12,
 462             K_RSA, B_NULL, M_SHA, H_SHA256),
 463     TLS_ECDH_ECDSA_WITH_NULL_SHA(
 464             0xC001, false, "TLS_ECDH_ECDSA_WITH_NULL_SHA", "",
 465             ProtocolVersion.PROTOCOLS_TO_12,


 504             0x0022, false, "TLS_KRB5_WITH_DES_CBC_MD5", "",
 505             ProtocolVersion.PROTOCOLS_TO_11,
 506             K_KRB5, B_DES, M_MD5, H_SHA256),
 507     TLS_KRB5_EXPORT_WITH_DES_CBC_40_SHA(
 508             0x0026, false, "TLS_KRB5_EXPORT_WITH_DES_CBC_40_SHA", "",
 509             ProtocolVersion.PROTOCOLS_TO_10,
 510             K_KRB5_EXPORT, B_DES_40, M_SHA, H_SHA256),
 511     TLS_KRB5_EXPORT_WITH_DES_CBC_40_MD5(
 512             0x0029, false, "TLS_KRB5_EXPORT_WITH_DES_CBC_40_MD5", "",
 513             ProtocolVersion.PROTOCOLS_TO_10,
 514             K_KRB5_EXPORT, B_DES_40, M_MD5, H_SHA256),
 515     TLS_KRB5_EXPORT_WITH_RC4_40_SHA(
 516             0x0028, false, "TLS_KRB5_EXPORT_WITH_RC4_40_SHA", "",
 517             ProtocolVersion.PROTOCOLS_TO_10,
 518             K_KRB5_EXPORT, B_RC4_40, M_SHA, H_SHA256),
 519     TLS_KRB5_EXPORT_WITH_RC4_40_MD5(
 520             0x002B, false, "TLS_KRB5_EXPORT_WITH_RC4_40_MD5", "",
 521             ProtocolVersion.PROTOCOLS_TO_10,
 522             K_KRB5_EXPORT, B_RC4_40, M_MD5, H_SHA256),
 523 
 524     // Definition of the cipher suites that are not supported but the names
 525     // are known.
 526     TLS_CHACHA20_POLY1305_SHA256(                    // TLS 1.3
 527             "TLS_CHACHA20_POLY1305_SHA256", 0x1303),
 528     TLS_AES_128_CCM_SHA256(                          // TLS 1.3
 529             "TLS_AES_128_CCM_SHA256", 0x1304),
 530     TLS_AES_128_CCM_8_SHA256(                        // TLS 1.3
 531             "TLS_AES_128_CCM_8_SHA256", 0x1305),
 532 
 533     // Remaining unsupported cipher suites defined in RFC2246.
 534     CS_0006("SSL_RSA_EXPORT_WITH_RC2_CBC_40_MD5",           0x0006),
 535     CS_0007("SSL_RSA_WITH_IDEA_CBC_SHA",                    0x0007),
 536     CS_000B("SSL_DH_DSS_EXPORT_WITH_DES40_CBC_SHA",         0x000b),
 537     CS_000C("SSL_DH_DSS_WITH_DES_CBC_SHA",                  0x000c),
 538     CS_000D("SSL_DH_DSS_WITH_3DES_EDE_CBC_SHA",             0x000d),
 539     CS_000E("SSL_DH_RSA_EXPORT_WITH_DES40_CBC_SHA",         0x000e),
 540     CS_000F("SSL_DH_RSA_WITH_DES_CBC_SHA",                  0x000f),
 541     CS_0010("SSL_DH_RSA_WITH_3DES_EDE_CBC_SHA",             0x0010),
 542 
 543     // SSL 3.0 Fortezza cipher suites
 544     CS_001C("SSL_FORTEZZA_DMS_WITH_NULL_SHA",               0x001c),
 545     CS_001D("SSL_FORTEZZA_DMS_WITH_FORTEZZA_CBC_SHA",       0x001d),
 546 
 547     // 1024/56 bit exportable cipher suites from expired internet draft
 548     CS_0062("SSL_RSA_EXPORT1024_WITH_DES_CBC_SHA",          0x0062),
 549     CS_0063("SSL_DHE_DSS_EXPORT1024_WITH_DES_CBC_SHA",      0x0063),
 550     CS_0064("SSL_RSA_EXPORT1024_WITH_RC4_56_SHA",           0x0064),
 551     CS_0065("SSL_DHE_DSS_EXPORT1024_WITH_RC4_56_SHA",       0x0065),
 552     CS_0066("SSL_DHE_DSS_WITH_RC4_128_SHA",                 0x0066),
 553 
 554     // Netscape old and new SSL 3.0 FIPS cipher suites
 555     // see http://www.mozilla.org/projects/security/pki/nss/ssl/fips-ssl-ciphersuites.html
 556     CS_FFE0("NETSCAPE_RSA_FIPS_WITH_3DES_EDE_CBC_SHA",      0xffe0),
 557     CS_FFE1("NETSCAPE_RSA_FIPS_WITH_DES_CBC_SHA",           0xffe1),
 558     CS_FEFE("SSL_RSA_FIPS_WITH_DES_CBC_SHA",                0xfefe),
 559     CS_FEFF("SSL_RSA_FIPS_WITH_3DES_EDE_CBC_SHA",           0xfeff),
 560 
 561     // Unsupported Kerberos cipher suites from RFC 2712
 562     CS_0021("TLS_KRB5_WITH_IDEA_CBC_SHA",                   0x0021),
 563     CS_0025("TLS_KRB5_WITH_IDEA_CBC_MD5",                   0x0025),
 564     CS_0027("TLS_KRB5_EXPORT_WITH_RC2_CBC_40_SHA",          0x0027),
 565     CS_002A("TLS_KRB5_EXPORT_WITH_RC2_CBC_40_MD5",          0x002a),
 566 
 567     // Unsupported cipher suites from RFC 4162
 568     CS_0096("TLS_RSA_WITH_SEED_CBC_SHA",                    0x0096),
 569     CS_0097("TLS_DH_DSS_WITH_SEED_CBC_SHA",                 0x0097),
 570     CS_0098("TLS_DH_RSA_WITH_SEED_CBC_SHA",                 0x0098),
 571     CS_0099("TLS_DHE_DSS_WITH_SEED_CBC_SHA",                0x0099),
 572     CS_009A("TLS_DHE_RSA_WITH_SEED_CBC_SHA",                0x009a),
 573     CS_009B("TLS_DH_anon_WITH_SEED_CBC_SHA",                0x009b),
 574 


< prev index next >