提交 4a8e9c22 编写于 作者: R Rich Salz

Move 3DES from HIGH to MEDIUM

Reviewed-by: NViktor Dukhovni <viktor@openssl.org>
上级 3fd60dc4
...@@ -4,6 +4,8 @@ ...@@ -4,6 +4,8 @@
Changes between 1.0.2g and 1.1.0 [xx XXX xxxx] Changes between 1.0.2g and 1.1.0 [xx XXX xxxx]
*) Triple-DES ciphers have been moved from HIGH to MEDIUM.
*) To enable users to have their own config files and build file templates, *) To enable users to have their own config files and build file templates,
Configure looks in the directory indicated by the environment variable Configure looks in the directory indicated by the environment variable
OPENSSL_LOCAL_CONFIG_DIR as well as the in-source Configurations/ OPENSSL_LOCAL_CONFIG_DIR as well as the in-source Configurations/
......
...@@ -208,7 +208,7 @@ static SSL_CIPHER ssl3_ciphers[] = ...@@ -208,7 +208,7 @@ static SSL_CIPHER ssl3_ciphers[] =
SSL_SHA1, SSL_SHA1,
SSL3_VERSION, TLS1_2_VERSION, SSL3_VERSION, TLS1_2_VERSION,
DTLS1_VERSION, DTLS1_2_VERSION, DTLS1_VERSION, DTLS1_2_VERSION,
SSL_HIGH | SSL_FIPS, SSL_MEDIUM | SSL_FIPS,
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
112, 112,
168, 168,
...@@ -223,7 +223,7 @@ static SSL_CIPHER ssl3_ciphers[] = ...@@ -223,7 +223,7 @@ static SSL_CIPHER ssl3_ciphers[] =
SSL_SHA1, SSL_SHA1,
SSL3_VERSION, TLS1_2_VERSION, SSL3_VERSION, TLS1_2_VERSION,
DTLS1_VERSION, DTLS1_2_VERSION, DTLS1_VERSION, DTLS1_2_VERSION,
SSL_NOT_DEFAULT | SSL_HIGH | SSL_FIPS, SSL_NOT_DEFAULT | SSL_MEDIUM | SSL_FIPS,
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
112, 112,
168, 168,
...@@ -238,7 +238,7 @@ static SSL_CIPHER ssl3_ciphers[] = ...@@ -238,7 +238,7 @@ static SSL_CIPHER ssl3_ciphers[] =
SSL_SHA1, SSL_SHA1,
SSL3_VERSION, TLS1_2_VERSION, SSL3_VERSION, TLS1_2_VERSION,
DTLS1_VERSION, DTLS1_2_VERSION, DTLS1_VERSION, DTLS1_2_VERSION,
SSL_HIGH | SSL_FIPS, SSL_MEDIUM | SSL_FIPS,
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
112, 112,
168, 168,
...@@ -253,7 +253,7 @@ static SSL_CIPHER ssl3_ciphers[] = ...@@ -253,7 +253,7 @@ static SSL_CIPHER ssl3_ciphers[] =
SSL_SHA1, SSL_SHA1,
SSL3_VERSION, TLS1_2_VERSION, SSL3_VERSION, TLS1_2_VERSION,
DTLS1_VERSION, DTLS1_2_VERSION, DTLS1_VERSION, DTLS1_2_VERSION,
SSL_NOT_DEFAULT | SSL_HIGH | SSL_FIPS, SSL_NOT_DEFAULT | SSL_MEDIUM | SSL_FIPS,
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
112, 112,
168, 168,
...@@ -960,7 +960,7 @@ static SSL_CIPHER ssl3_ciphers[] = ...@@ -960,7 +960,7 @@ static SSL_CIPHER ssl3_ciphers[] =
SSL_SHA1, SSL_SHA1,
SSL3_VERSION, TLS1_2_VERSION, SSL3_VERSION, TLS1_2_VERSION,
DTLS1_VERSION, DTLS1_2_VERSION, DTLS1_VERSION, DTLS1_2_VERSION,
SSL_HIGH | SSL_FIPS, SSL_MEDIUM | SSL_FIPS,
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
112, 112,
168, 168,
...@@ -1020,7 +1020,7 @@ static SSL_CIPHER ssl3_ciphers[] = ...@@ -1020,7 +1020,7 @@ static SSL_CIPHER ssl3_ciphers[] =
SSL_SHA1, SSL_SHA1,
SSL3_VERSION, TLS1_2_VERSION, SSL3_VERSION, TLS1_2_VERSION,
DTLS1_VERSION, DTLS1_2_VERSION, DTLS1_VERSION, DTLS1_2_VERSION,
SSL_HIGH | SSL_FIPS, SSL_MEDIUM | SSL_FIPS,
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
112, 112,
168, 168,
...@@ -1080,7 +1080,7 @@ static SSL_CIPHER ssl3_ciphers[] = ...@@ -1080,7 +1080,7 @@ static SSL_CIPHER ssl3_ciphers[] =
SSL_SHA1, SSL_SHA1,
SSL3_VERSION, TLS1_2_VERSION, SSL3_VERSION, TLS1_2_VERSION,
DTLS1_VERSION, DTLS1_2_VERSION, DTLS1_VERSION, DTLS1_2_VERSION,
SSL_NOT_DEFAULT | SSL_HIGH | SSL_FIPS, SSL_NOT_DEFAULT | SSL_MEDIUM | SSL_FIPS,
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
112, 112,
168, 168,
...@@ -1293,7 +1293,7 @@ static SSL_CIPHER ssl3_ciphers[] = ...@@ -1293,7 +1293,7 @@ static SSL_CIPHER ssl3_ciphers[] =
SSL_SHA1, SSL_SHA1,
SSL3_VERSION, TLS1_2_VERSION, SSL3_VERSION, TLS1_2_VERSION,
DTLS1_VERSION, DTLS1_2_VERSION, DTLS1_VERSION, DTLS1_2_VERSION,
SSL_HIGH | SSL_FIPS, SSL_MEDIUM | SSL_FIPS,
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
112, 112,
168, 168,
...@@ -1338,7 +1338,7 @@ static SSL_CIPHER ssl3_ciphers[] = ...@@ -1338,7 +1338,7 @@ static SSL_CIPHER ssl3_ciphers[] =
SSL_SHA1, SSL_SHA1,
SSL3_VERSION, TLS1_2_VERSION, SSL3_VERSION, TLS1_2_VERSION,
DTLS1_VERSION, DTLS1_2_VERSION, DTLS1_VERSION, DTLS1_2_VERSION,
SSL_HIGH | SSL_FIPS, SSL_MEDIUM | SSL_FIPS,
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
112, 112,
168, 168,
...@@ -1383,7 +1383,7 @@ static SSL_CIPHER ssl3_ciphers[] = ...@@ -1383,7 +1383,7 @@ static SSL_CIPHER ssl3_ciphers[] =
SSL_SHA1, SSL_SHA1,
SSL3_VERSION, TLS1_2_VERSION, SSL3_VERSION, TLS1_2_VERSION,
DTLS1_VERSION, DTLS1_2_VERSION, DTLS1_VERSION, DTLS1_2_VERSION,
SSL_HIGH | SSL_FIPS, SSL_MEDIUM | SSL_FIPS,
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
112, 112,
168, 168,
...@@ -1699,7 +1699,7 @@ static SSL_CIPHER ssl3_ciphers[] = ...@@ -1699,7 +1699,7 @@ static SSL_CIPHER ssl3_ciphers[] =
SSL_SHA1, SSL_SHA1,
SSL3_VERSION, TLS1_2_VERSION, SSL3_VERSION, TLS1_2_VERSION,
DTLS1_VERSION, DTLS1_2_VERSION, DTLS1_VERSION, DTLS1_2_VERSION,
SSL_HIGH | SSL_FIPS, SSL_MEDIUM | SSL_FIPS,
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
112, 112,
168, 168,
...@@ -1823,7 +1823,7 @@ static SSL_CIPHER ssl3_ciphers[] = ...@@ -1823,7 +1823,7 @@ static SSL_CIPHER ssl3_ciphers[] =
SSL_SHA1, SSL_SHA1,
SSL3_VERSION, TLS1_2_VERSION, SSL3_VERSION, TLS1_2_VERSION,
DTLS1_VERSION, DTLS1_2_VERSION, DTLS1_VERSION, DTLS1_2_VERSION,
SSL_HIGH, SSL_MEDIUM,
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
112, 112,
168, 168,
...@@ -1838,7 +1838,7 @@ static SSL_CIPHER ssl3_ciphers[] = ...@@ -1838,7 +1838,7 @@ static SSL_CIPHER ssl3_ciphers[] =
SSL_SHA1, SSL_SHA1,
SSL3_VERSION, TLS1_2_VERSION, SSL3_VERSION, TLS1_2_VERSION,
DTLS1_VERSION, DTLS1_2_VERSION, DTLS1_VERSION, DTLS1_2_VERSION,
SSL_HIGH, SSL_MEDIUM,
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
112, 112,
168, 168,
...@@ -1853,7 +1853,7 @@ static SSL_CIPHER ssl3_ciphers[] = ...@@ -1853,7 +1853,7 @@ static SSL_CIPHER ssl3_ciphers[] =
SSL_SHA1, SSL_SHA1,
SSL3_VERSION, TLS1_2_VERSION, SSL3_VERSION, TLS1_2_VERSION,
DTLS1_VERSION, DTLS1_2_VERSION, DTLS1_VERSION, DTLS1_2_VERSION,
SSL_NOT_DEFAULT | SSL_HIGH, SSL_NOT_DEFAULT | SSL_MEDIUM,
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
112, 112,
168, 168,
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册