Update - OpenSSL 1.1.1-pre7-dev
This commit is contained in:
@@ -2,7 +2,11 @@
|
||||
|
||||
=head1 NAME
|
||||
|
||||
SSL_CTX_set_cipher_list, SSL_set_cipher_list - choose list of available SSL_CIPHERs
|
||||
SSL_CTX_set_cipher_list,
|
||||
SSL_set_cipher_list,
|
||||
SSL_CTX_set_ciphersuites,
|
||||
SSL_set_ciphersuites
|
||||
- choose list of available SSL_CIPHERs
|
||||
|
||||
=head1 SYNOPSIS
|
||||
|
||||
@@ -11,18 +15,49 @@ SSL_CTX_set_cipher_list, SSL_set_cipher_list - choose list of available SSL_CIPH
|
||||
int SSL_CTX_set_cipher_list(SSL_CTX *ctx, const char *str);
|
||||
int SSL_set_cipher_list(SSL *ssl, const char *str);
|
||||
|
||||
int SSL_CTX_set_ciphersuites(SSL_CTX *ctx, const char *str);
|
||||
int SSL_set_ciphersuites(SSL *s, const char *str);
|
||||
|
||||
=head1 DESCRIPTION
|
||||
|
||||
SSL_CTX_set_cipher_list() sets the list of available ciphers for B<ctx>
|
||||
using the control string B<str>. The format of the string is described
|
||||
SSL_CTX_set_cipher_list() sets the list of available ciphers (TLSv1.2 and below)
|
||||
for B<ctx> using the control string B<str>. The format of the string is described
|
||||
in L<ciphers(1)>. The list of ciphers is inherited by all
|
||||
B<ssl> objects created from B<ctx>.
|
||||
B<ssl> objects created from B<ctx>. This function does not impact TLSv1.3
|
||||
ciphersuites. Use SSL_CTX_set_ciphersuites() to configure those.
|
||||
|
||||
SSL_set_cipher_list() sets the list of ciphers only for B<ssl>.
|
||||
SSL_set_cipher_list() sets the list of ciphers (TLSv1.2 and below) only for
|
||||
B<ssl>.
|
||||
|
||||
SSL_CTX_set_ciphersuites() is used to configure the available TLSv1.3
|
||||
ciphersuites for B<ctx>. This is a simple colon (":") separated list of TLSv1.3
|
||||
ciphersuite names in order of perference. Valid TLSv1.3 ciphersuite names are:
|
||||
|
||||
=over 4
|
||||
|
||||
=item TLS_AES_128_GCM_SHA256
|
||||
|
||||
=item TLS_AES_256_GCM_SHA384
|
||||
|
||||
=item TLS_CHACHA20_POLY1305_SHA256
|
||||
|
||||
=item TLS_AES_128_CCM_SHA256
|
||||
|
||||
=item TLS_AES_128_CCM_8_SHA256
|
||||
|
||||
=back
|
||||
|
||||
An empty list is permissible. The default value for the this setting is:
|
||||
|
||||
"TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256:TLS_AES_128_GCM_SHA256"
|
||||
|
||||
SSL_set_ciphersuites() is the same as SSL_CTX_set_ciphersuites() except it
|
||||
configures the ciphersuites for B<ssl>.
|
||||
|
||||
=head1 NOTES
|
||||
|
||||
The control string B<str> should be universally usable and not depend
|
||||
The control string B<str> for SSL_CTX_set_cipher_list() and
|
||||
SSL_set_cipher_list() should be universally usable and not depend
|
||||
on details of the library configuration (ciphers compiled in). Thus no
|
||||
syntax checking takes place. Items that are not recognized, because the
|
||||
corresponding ciphers are not compiled in or because they are mistyped,
|
||||
@@ -55,6 +90,9 @@ and the handshake will fail.
|
||||
SSL_CTX_set_cipher_list() and SSL_set_cipher_list() return 1 if any cipher
|
||||
could be selected and 0 on complete failure.
|
||||
|
||||
SSL_CTX_set_ciphersuites() and SSL_set_ciphersuites() return 1 if the requested
|
||||
ciphersuite list was configured, and 0 otherwise.
|
||||
|
||||
=head1 SEE ALSO
|
||||
|
||||
L<ssl(7)>, L<SSL_get_ciphers(3)>,
|
||||
@@ -64,7 +102,7 @@ L<ciphers(1)>
|
||||
|
||||
=head1 COPYRIGHT
|
||||
|
||||
Copyright 2000-2016 The OpenSSL Project Authors. All Rights Reserved.
|
||||
Copyright 2000-2018 The OpenSSL Project Authors. All Rights Reserved.
|
||||
|
||||
Licensed under the OpenSSL license (the "License"). You may not use
|
||||
this file except in compliance with the License. You can obtain a copy
|
||||
|
||||
Reference in New Issue
Block a user