• E
    Rework the default cipherlist. · a556f342
    Emilia Kasper 提交于
     - Always prefer forward-secure handshakes.
     - Consistently order ECDSA above RSA.
     - Next, always prefer AEADs to non-AEADs, irrespective of strength.
     - Within AEADs, prefer GCM > CHACHA > CCM for a given strength.
     - Prefer TLS v1.2 ciphers to legacy ciphers.
     - Remove rarely used DSS, IDEA, SEED, CAMELLIA, CCM from the default
       list to reduce ClientHello bloat.
    Reviewed-by: NRich Salz <rsalz@openssl.org>
    a556f342
可在Tags中查看这些版本中当前仓库的状态.
CHANGES 508.0 KB